Malware

Downloader.Win32.YXdown.re removal guide

Malware Removal

The Downloader.Win32.YXdown.re is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.YXdown.re virus can do?

  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
ggstats.box.bainuonet.com
a.tomx.xyz

How to determine Downloader.Win32.YXdown.re?


File Info:

crc32: B65101ED
md5: 71bc1d68c38232852416bafa34162f55
name: ____________________________________________________________________________________________________
sha1: a331ac7cfc3bfe3940cd0b86f64bc2faf9323b87
sha256: 382dafbccf335dd2c794445c2e741c431331183aee266c927eb497e2d5039cd8
sha512: 8284c6408c69118863b5ebfde7aca7a6d5e35647f86f49a4785303f52bdb77b4da9455c0e717829104bd900cc200c2cf1b8c2940bbe3d8476ffc4d63c169c93d
ssdeep: 98304:Yq2AGzz/583pvNP+J/2puup6CxPm+2d/NW+3Zo7oM56:+z/kD+JezFxu3/3C7P56
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015-2016 x6606x5c71x767ex8bfax4fe1x606fx79d1x6280x6709x9650x516cx53f8
InternalName: gamebox
FileVersion: 22, 0, 0, 1
Comments: x4e50x6e38x6e38x620fx76d2x5b89x88c5x5411x5bfc
ProductName: x4e50x6e38x6e38x620fx76d2x5b89x88c5x5411x5bfc
ProductVersion: 22, 0, 0, 1
FileDescription: x4e50x6e38x6e38x620fx76d2x5b89x88c5x5411x5bfc
OriginalFilename: gamebox.exe
Translation: 0x0804 0x04b0

Downloader.Win32.YXdown.re also known as:

MicroWorld-eScanTrojan.GenericKD.32787928
McAfeeGenericRXGJ-TG!71BC1D68C382
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0053469a1 )
BitDefenderTrojan.GenericKD.32787928
K7GWRiskware ( 0053469a1 )
Cybereasonmalicious.8c3823
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.32787928
Kasperskynot-a-virus:Downloader.Win32.YXdown.re
AlibabaRiskWare:Win32/YouXun.7a75d5e2
NANO-AntivirusTrojan.Win32.YXdown.fxmvsh
AegisLabTrojan.UKP.YouXun.4!c
RisingAdware.Downloader!1.B962 (CLOUD)
Ad-AwareTrojan.GenericKD.32787928
EmsisoftTrojan.GenericKD.32787928 (B)
ZillyaTool.YouXun.Win32.218
Invinceaheuristic
McAfee-GW-EditionGenericRXGJ-TG!71BC1D68C382
FireEyeGeneric.mg.71bc1d68c3823285
SophosGeneric PUA KD (PUA)
CyrenW32/S-8eff144b!Eldorado
JiangminRiskTool.Agent.atv
WebrootW32.Trojan.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F44DD8
ZoneAlarmnot-a-virus:Downloader.Win32.YXdown.re
MicrosoftPUA:Win32/Youxun
ALYacTrojan.GenericKD.32787928
MAXmalware (ai score=100)
VBA32Downloader.YXdown
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/RiskWare.YouXun.B
YandexPUA.Downloader!
IkarusPUA.RiskWare.Youxun
MaxSecureTrojan.Malware.11882074.susgen
FortinetRiskware/YouXun
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Downloader.Win32.YXdown.re?

Downloader.Win32.YXdown.re removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment