Malware

Downloader.Win32.Yantai.hkg removal tips

Malware Removal

The Downloader.Win32.Yantai.hkg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Yantai.hkg virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Downloader.Win32.Yantai.hkg?


File Info:

crc32: A8EBAA51
md5: 8ab4b6f6c90f45a7a291dd2dcb3898fc
name: qq____________609_4152_4152-.exe
sha1: 967dc609f075ceac52cf468352209c5371a6b03c
sha256: 9cba0c19b76be0dd46c3eb5c5aad3c3e53e093bc183210ccdca6ce553c8d0ef3
sha512: 4116c63928692ec76e2b5370f554ce88fb428e1a8cfab6ec6f1e94cbcf82c5ac3dff936acf007c7e650988a4700278a5a7cf8df289943ea25ed78cf78c5ac771
ssdeep: 98304:IhVPyPMCbPkGSIAc5TXGQMS5iNhfQ9e6vXGpbM16AxziYeYwz/pckDLVmTnYcdX:IrOPxac5F849+u6AcrvLVgnY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: JJDownLo.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: JJDownLo.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Yantai.hkg also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.33284136
FireEyeGeneric.mg.8ab4b6f6c90f45a7
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!8AB4B6F6C90F
K7AntiVirusTrojan-Downloader ( 0054ead51 )
BitDefenderTrojan.GenericKD.33284136
K7GWTrojan-Downloader ( 0054ead51 )
TrendMicroTROJ_GEN.R015C0GBD20
BitDefenderThetaGen:NN.ZexaF.34090.@J0@aaST2wij
F-ProtW32/S-bc220906!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R015C0GBD20
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.33284136
Kasperskynot-a-virus:Downloader.Win32.Yantai.hkg
AlibabaDownloader:Win32/Yantai.041bc397
ViRobotTrojan.Win32.Z.Crypt.6521344.A
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33284136 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
SophosGeneric PUA JG (PUA)
APEXMalicious
CyrenW32/S-bc220906!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLRiskWare[Downloader]/Win32.Yantai
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Generic.D1FBE028
AhnLab-V3PUP/Win32.Yantai.R325966
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.hkg
Acronissuspicious
ALYacTrojan.GenericKD.33284136
MAXmalware (ai score=84)
Ad-AwareTrojan.GenericKD.33284136
PandaTrj/Genetic.gen
RisingTrojan.Crypto!8.364 (CLOUD)
IkarusTrojan.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.95F7!tr
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/HEUR/QVM19.1.2D9F.Malware.Gen

How to remove Downloader.Win32.Yantai.hkg?

Downloader.Win32.Yantai.hkg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment