Malware

Downloader.Win32.Yantai.hnu removal guide

Malware Removal

The Downloader.Win32.Yantai.hnu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Yantai.hnu virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Downloader.Win32.Yantai.hnu?


File Info:

crc32: E8C922CF
md5: 6c16eaf22f3721c5b190560471932cd9
name: pdf.exe
sha1: 23efbadc91df8c8457d2a8cce2294610962e5459
sha256: 373b1f2023541cd5fb12537905df1b12016da5fc64ad9513da64eab51f4bc296
sha512: 4e65ef3c15cc3d98872891a0e06c63d5bc248465d44ad5082939e2f85f8fc322acc1f79d413dc1bbe37b8c0d3194248ff124b1c00ea47eb1eed371fc4fe77957
ssdeep: 196608:pgP49WKaKeeyCZu0uazJMxOPgNRTntGc+k2kJVyc:po7KdeTCjLMx0gXLtGcJVyc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: JJDownLo.exe
FileVersion: 1.0.0.1
OriginalFilename: JJDownLo.exe
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Downloader.Win32.Yantai.hnu also known as:

BkavW32.AIDetectVM.malware2
SangforMalware
CyrenW32/Yantai.E.gen!Eldorado
AvastWin32:Malware-gen
Kasperskynot-a-virus:Downloader.Win32.Yantai.hnu
AlibabaDownloader:Win32/Yantai.9897d626
APEXMalicious
FortinetRiskware/Yantai
FireEyeGeneric.mg.6c16eaf22f3721c5
SentinelOneDFI – Malicious PE
F-ProtW32/Yantai.E.gen!Eldorado
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.hnu
MicrosoftTrojan:Win32/Casur.A!cl
RisingTrojan.Crypto!8.364 (TFE:dGZlOgXeq1ddwZKWNQ)
eGambitUnsafe.AI_Score_98%
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Downloader.Win32.Yantai.hnu?

Downloader.Win32.Yantai.hnu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment