Malware

Downloader.Win32.YXdown.fi removal tips

Malware Removal

The Downloader.Win32.YXdown.fi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.YXdown.fi virus can do?

  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
box2.bainuonet.com
ggstats.box.bainuonet.com
a.tomx.xyz

How to determine Downloader.Win32.YXdown.fi?


File Info:

crc32: 87B7756E
md5: 2de4432d9d62f7f66b5640691625d01d
name: yxs_czijha.exe
sha1: 86a2dafe8a28f5a869c3e4da54797d56b408e5cd
sha256: 29afb30c3641f39222f3ee54bc5f7e86103d72141603eda847edecd34d497bd1
sha512: a4599a1e2e70ebad3138a9fc6fa8b752e38e9902a4be783bb25307696e3e31dc89cac28e54287b7911a004329559bc8b5ff93ef5a2b4eb956ae73cc5906f7ae5
ssdeep: 98304:0WWwmYHne9XC0rfSRxPQ1PmDyEmQWyPgDwl73O:0WWwmInLGcKuDyEmQWD0lrO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016 x6606x5c71x767ex8bfax4fe1x606fx79d1x6280x6709x9650x516cx53f8
InternalName: gamebox
FileVersion: 9, 0, 2, 5
Comments: x6e38x620fx76d2x5b89x88c5x5411x5bfc
ProductName: x4e50x6e38x6e38x620fx76d2x5b89x88c5x5411x5bfc
ProductVersion: 9, 0, 2, 5
FileDescription: x4e50x6e38x6e38x620fx76d2x5b89x88c5x5411x5bfc
OriginalFilename: gamebox.exe
Translation: 0x0804 0x04b0

Downloader.Win32.YXdown.fi also known as:

MicroWorld-eScanTrojan.GenericKD.41215366
CAT-QuickHealTrojan.Youxun
McAfeeGenericRXGJ-TG!2DE4432D9D62
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 00502b2a1 )
BitDefenderTrojan.GenericKD.41215366
K7GWUnwanted-Program ( 00502b2a1 )
Cybereasonmalicious.d9d62f
TrendMicroPUA_YOUXUN.GA
CyrenW32/S-0476c9d0!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallPUA_YOUXUN.GA
Paloaltogeneric.ml
GDataTrojan.GenericKD.41215366
Kasperskynot-a-virus:Downloader.Win32.YXdown.fi
AlibabaDownloader:Win32/YXdown.a7359808
NANO-AntivirusTrojan.Win32.Fakealert.eydntx
ViRobotAdware.Strictor.4081256
Ad-AwareTrojan.GenericKD.41215366
SophosGeneric PUA IG (PUA)
ComodoApplicUnwnt@#hiwbg7me4hti
DrWebTrojan.Fakealert.58242
ZillyaAdware.YouXunCRTD.Win32.5326
Invinceaheuristic
McAfee-GW-EditionGenericRXGJ-TG!2DE4432D9D62
SentinelOneDFI – Malicious PE
FireEyeGeneric.mg.2de4432d9d62f7f6
EmsisoftTrojan.GenericKD.41215366 (B)
APEXMalicious
F-ProtW32/S-0476c9d0!Eldorado
JiangminDownloader.YXdown.af
WebrootW32.Trojan.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D274E586
ZoneAlarmnot-a-virus:Downloader.Win32.YXdown.fi
MicrosoftPUA:Win32/Youxun
AhnLab-V3PUP/Win32.Generic.C1913277
VBA32Trojan.FakeAlert
ALYacTrojan.GenericKD.41215366
MAXmalware (ai score=100)
MalwarebytesPUP.Optional.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.B
RisingAdware.Downloader!1.B962 (CLASSIC)
YandexRiskWare.YouXun!
IkarusPUA.RiskWare.Youxun
eGambitGeneric.Malware
FortinetRiskware/YouXun
AVGFileRepMetagen [PUP]
PandaPUP/Generic
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.73725327.susgen

How to remove Downloader.Win32.YXdown.fi?

Downloader.Win32.YXdown.fi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment