Malware

Downloader.Win32.Yantai.hnr removal

Malware Removal

The Downloader.Win32.Yantai.hnr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Yantai.hnr virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Downloader.Win32.Yantai.hnr?


File Info:

crc32: 8B39CE42
md5: 7e1d0ffb8b973a267a8232fb17c6d484
name: _______________51_351462.exe
sha1: 3dd332d382cc1f3c379d0e1c9c9c3bae9f4214ba
sha256: 9d45f30bcf5497b6541b2fe872ff1d01d129f0e3acd91d10d5116e05dff1b652
sha512: 92b02d4dc856b2cdbd0e9cb7c868c342757214b1a541257b76a0ddd9682dab963c0008cfb703e8a8f42f9f8055063560c592fcf7f12e9ec50cd956b28ef2125c
ssdeep: 196608:RmxD18NouGUDPof7KSwu8Z7+1LD76ISm4KqQaY:RmB1ZikuSwNK4IvqQaY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: JJDownLo.exe
FileVersion: 1.0.0.1
OriginalFilename: JJDownLo.exe
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Downloader.Win32.Yantai.hnr also known as:

BkavW32.AIDetectVM.malware
CylanceUnsafe
SangforMalware
F-ProtW32/Yantai.E.gen!Eldorado
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.Yantai.hnr
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA DN (PUA)
APEXMalicious
CyrenW32/Yantai.E.gen!Eldorado
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.hnr
MicrosoftPUA:Win32/Presenoker
SentinelOneDFI – Malicious PE
McAfeeArtemis!7E1D0FFB8B97
RisingTrojan.Crypto!8.364 (TFE:dGZlOgXeq1ddwZKWNQ)
eGambitUnsafe.AI_Score_94%
WebrootW32.Trojan.Gen
AVGFileRepMalware

How to remove Downloader.Win32.Yantai.hnr?

Downloader.Win32.Yantai.hnr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment