Malware

Downloader.Win32.Yantai.hlu removal tips

Malware Removal

The Downloader.Win32.Yantai.hlu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Yantai.hlu virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

softlog.pdf00.cn

How to determine Downloader.Win32.Yantai.hlu?


File Info:

crc32: 534A1B49
md5: 618a08e0e2fffe97db9750a9f4bb9a95
name: setup_pdfreader_pdfreaderdate01nodkpk_v1.0_silent.exe
sha1: 4c2b97a0b215678defd1acd6d9261c4375a1ac75
sha256: 5a095450d38cecea1874ff1d1866e92a4a902813864697e73a0631690abe5714
sha512: 78b2e448284f63f8087555b26f7888b3f964fd3e14821cc1f7b078a27a4d164d7fb9873813db8bc504df17c8a05ee5b63f211875e4ddea61cbf87fdf3fefe792
ssdeep: 393216:mz2oE6SVSjcRy2pMiZnDtueGUPWiAZxKva7gujKFPdG7W6:xqkSjcZp1ZBGUPWioxKPuQH6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019 x4e0ax6d77x5b50x672ax7f51x7edcx79d1x6280x6709x9650x516cx53f8
InternalName: Setup.exe
CompanyName: x4e0ax6d77x5b50x672ax7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x98cex4e91PDFx9605x8bfbx5668
ProductVersion: 2.0.0.1
FileDescription: x98cex4e91PDFx9605x8bfbx5668x5b89x88c5x7a0bx5e8f
OriginalFilename: Setup.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Yantai.hlu also known as:

MicroWorld-eScanGen:Variant.Graftor.711421
FireEyeGeneric.mg.618a08e0e2fffe97
McAfeePUP-XJF-ZF
ALYacGen:Variant.Graftor.711421
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 00554ed11 )
BitDefenderGen:Variant.Graftor.711421
K7GWTrojan-Downloader ( 00554ed11 )
Invinceaheuristic
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.711421
Kasperskynot-a-virus:Downloader.Win32.Yantai.hlu
AlibabaDownloader:Win32/Yantai.fac6aa2e
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Graftor.711421 (B)
TrendMicroTROJ_GEN.R002C0PC520
McAfee-GW-EditionPUP-XJF-ZF
IkarusTrojan-Downloader.Win32.Adload
CyrenW32/Application.MFVM-2386
JiangminDownloader.Generic.asac
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Bitrep
ArcabitTrojan.Graftor.DADAFD
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.hlu
MicrosoftPUA:Win32/CoinMiner
AhnLab-V3PUP/Win32.Agent.R304262
VBA32BScope.TrojanDownloader.Adload
Ad-AwareGen:Variant.Graftor.711421
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kaobeitu.C potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PC520
RisingPUF.Kaobeitu!8.1124B (CLOUD)
FortinetRiskware/Generic_PUA_FJ
AVGWin32:Malware-gen
Qihoo-360Generic/Trojan.ffa

How to remove Downloader.Win32.Yantai.hlu?

Downloader.Win32.Yantai.hlu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment