PUA

PUA:Win32/Youfile removal instruction

Malware Removal

The PUA:Win32/Youfile is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Youfile virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
st.file.pet

How to determine PUA:Win32/Youfile?


File Info:

crc32: 17AAB756
md5: d3ae87b5d7874fa3e29362c656cb06ca
name: D3AE87B5D7874FA3E29362C656CB06CA.mlw
sha1: 6fe64dd31f0206553edac0b12bcf87609a2d8c4c
sha256: ca63a9afb5e6ec2b2f55dab6262bcf071e7c3b99824aec06ebd53b99e43db23d
sha512: 03f7a5cfe5da569203f11f5eb57a0aa7de99df668e9db813d65427b159c3104cffd55ce6cdfb554faebcbdeddf076eb5a5c90352be1a6a9c3bf11a9e6cfe530d
ssdeep: 3072:JCbJZH0cR3kSmgNstQulJbtRYUk00gYp8hyiYXYYD33PBjS8nYKYlUfDMUYa4YB:JmR3kSaZ40q3P/MGUjts
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

PUA:Win32/Youfile also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.85866
FireEyeGen:Variant.Bulz.85866
CAT-QuickHealPUA.Arturarake.Gen
ALYacGen:Variant.Bulz.85866
CylanceUnsafe
VIPRENSIS.Adware.Agent
SangforMalware
K7AntiVirusAdware ( 004fc05d1 )
BitDefenderGen:Variant.Bulz.85866
K7GWAdware ( 004fc05d1 )
Cybereasonmalicious.5d7874
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:Downloader.Win32.LMN.vmih
AlibabaDownloader:Win32/Generic.b9d43216
NANO-AntivirusRiskware.Nsis.Adw.eerowy
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Falsesign.Wrgo
Ad-AwareGen:Variant.Bulz.85866
SophosGeneric PUA GP (PUA)
ComodoApplicUnwnt@#3tvhscm5oap0u
F-SecureHeuristic.HEUR/AGEN.1127157
DrWebAdware.Downware.17549
ZillyaTrojan.StrictorCRTD.Win32.4889
TrendMicroTROJ_GEN.R002C0GA921
McAfee-GW-EditionArtemis!PUP
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Suspicious PE – Adware
AviraHEUR/AGEN.1127157
MAXmalware (ai score=82)
MicrosoftPUA:Win32/Youfile
ArcabitTrojan.Bulz.D14F6A
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.vmih
GDataGen:Variant.Bulz.85866
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.Adload.R191726
McAfeeArtemis!D3AE87B5D787
VBA32Downloader.LMN
MalwarebytesInstallCore.Adware.Bundler.DDS
PandaTrj/CI.A
ESET-NOD32NSIS/Adware.Agent.Q
TrendMicro-HouseCallTROJ_GEN.R002C0GA921
RisingAdware.NSIS/Agent!1.A9CC (CLASSIC)
FortinetAdware/Agent
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Virus.Downloader.f3c

How to remove PUA:Win32/Youfile?

PUA:Win32/Youfile removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment