Malware

About “Downloader.Win32.Yantai.hnx” infection

Malware Removal

The Downloader.Win32.Yantai.hnx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Yantai.hnx virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

Related domains:

update.tfblzp.com
i.tfblzp.com
xzqlog.tfblzp.com

How to determine Downloader.Win32.Yantai.hnx?


File Info:

crc32: F634B736
md5: c09e545ba02b3166451c1ffd613755ee
name: E59CB0E79083E999A8E890BDE5858DE5AE89E8A385E7BBBFE889B2E4B8ADE69687E78988_id163163_42989.exe
sha1: e0c1f3725ad08c74c4ee0d60856baba89186a23c
sha256: 43686f4b894cd8da04101ea978cf380d2ced2c93d9689d16ec6e9079b575145f
sha512: 084e3c958aadbe274d7474edde458be931f8621e6e5abc5c05fd927f84e7885d628fc6ff8eb4f1fd5e3a073ad5a184ba7443f208edbb6b628cd8cc794d91e1e6
ssdeep: 98304:selr9XAarDpFYtb87nKRyywf3NCZGRWm7qqD5g1IWLJOnpCC2rSt1gLFblddXdS:XpFYy7jywf3EZ8Wm7Vg1dap2r/F5s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: JJDownLo.exe
FileVersion: 1.0.0.1
OriginalFilename: JJDownLo.exe
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Downloader.Win32.Yantai.hnx also known as:

BkavW32.AIDetectVM.malware
McAfeeArtemis!C09E545BA02B
SangforMalware
K7AntiVirusTrojan-Downloader ( 0054ead51 )
K7GWTrojan-Downloader ( 0054ead51 )
CyrenW32/Yantai.E.gen!Eldorado
SymantecPUA.Gen.2
Kasperskynot-a-virus:Downloader.Win32.Yantai.hnx
RisingTrojan.Crypto!8.364 (TFE:dGZlOgXeq1ddwZKWNQ)
SophosGeneric PUA OA (PUA)
McAfee-GW-EditionArtemis!Trojan
F-ProtW32/Yantai.E.gen!Eldorado
WebrootW32.Trojan.Gen
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.hnx
MicrosoftTrojan:Win32/Fuery.C!cl
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_94%
FortinetRiskware/Yantai
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Downloader.Win32.Yantai.hnx?

Downloader.Win32.Yantai.hnx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment