Malware

Downloader.Win32.YXdown.pef removal tips

Malware Removal

The Downloader.Win32.YXdown.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.YXdown.pef virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Generates some ICMP traffic

Related domains:

api.pcsoft.jshhdian.com
ggstats.yb.jshhdian.com
eoud.dgygpx.com
www.baidu.com
api.yb.jshhdian.com
poik.dgygpx.com
ymte.sgdebao.com

How to determine Downloader.Win32.YXdown.pef?


File Info:

crc32: 75959336
md5: 892005f16ac56cbf0025b12a9819f3ed
name: adobe-photoshop_24_242.exe
sha1: 6f052bd92db539237061239218aabcf3ac9655ad
sha256: aa4f377a6edbbcd26bc418a07d8aba66272b2ab34648e17910f408ab7177f7f4
sha512: 92fd83c73f54b7113988bac06694670b572047c85c18f9809e6fefda5232410485612f72dd7fe393609f865e65bfeec2e629e27d860d7c6d2a377b6dd0552fed
ssdeep: 98304:7djrfbWvOUlCnJ+I9P0ABLGejAMJ8C2IXDOXqHBQ+RSQnhj1Emq3v05hX6mx3o1q:dCO0E0ABLlJfCQjqX3vU3IrftzUv
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 3.0.1.2
ProductName: x6781x901fx4e0bx8f7dx5668
ProductVersion: 3.0.1.2
FileDescription: x6781x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x03a8

Downloader.Win32.YXdown.pef also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42284019
FireEyeGeneric.mg.892005f16ac56cbf
CAT-QuickHealPUA.IgenericRI.S10596407
ALYacTrojan.GenericKD.42284019
ZillyaTool.YouXun.Win32.803
K7AntiVirusRiskware ( 0050b49d1 )
BitDefenderTrojan.GenericKD.42284019
K7GWRiskware ( 0050b49d1 )
Cybereasonmalicious.92db53
BitDefenderThetaGen:NN.ZexaF.34084.@pLfaqRCqwnj
CyrenW32/S-d8efc1c1!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.42284019
Kasperskynot-a-virus:HEUR:Downloader.Win32.YXdown.pef
Ad-AwareTrojan.GenericKD.42284019
F-SecurePrivacyRisk.SPR/GameTool.Gen8
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.42284019 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-d8efc1c1!Eldorado
JiangminDownloader.YXdown.bz
MaxSecureTrojan.Malware.74721109.susgen
AviraSPR/GameTool.Gen8
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D28533F3
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.YXdown.pef
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Malware/Win32.Generic.C3974891
McAfeeGenericRXAA-AA!892005F16AC5
MAXmalware (ai score=83)
VBA32Downloader.YXdown
MalwarebytesRiskWare.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.H
RisingAdware.Downloader!1.B962 (RDMK:cmRtazqNJNepVcp8MfFXEqb69QTV)
IkarusPUA.RiskWare.Youxun
eGambitUnsafe.AI_Score_99%
FortinetW32/GenericKD.32784984!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Virus.Downloader.b00

How to remove Downloader.Win32.YXdown.pef?

Downloader.Win32.YXdown.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment