PUA

About “PUA:Win32/Youxun” infection

Malware Removal

The PUA:Win32/Youxun is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Youxun virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUA:Win32/Youxun?


File Info:

crc32: E104ACF3
md5: f063a1e88c8cee2633bd2a0610792a06
name: ______orc__________________v8.1______________________205243882.exe
sha1: 1e2e119a5c0ad5d625fb29b21e578e915f34e596
sha256: 23dd15e8b6caae4d9849b62ed7755a7eff4c92e196f1d7d04352c360b4a3c1f3
sha512: b7199e95aa9b0f47bae4c09386f264bdf071d0f5a388e082f01b2ab51bc5d5e1fdfc8d4e6fcde3a1fc812e8c8f9a7b208aeb399ec347cd6727fb9279c35c5674
ssdeep: 196608:3VOjuLuNfsj89Z4w66PV9fd6Hoj+5FT4zqyRrS:PuNfsCP/8HW+oWiS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019 Shanghai Youwo Information Technology Co., Ltd.
InternalName: Setup
FileVersion: 1, 2, 3, 7
Comments: x5b89x88c5x5411x5bfc
ProductName: x5b89x88c5x5411x5bfc
ProductVersion: 1, 2, 3, 7
FileDescription: x5b89x88c5x5411x5bfc
OriginalFilename: Setup.exe
Translation: 0x0804 0x04b0

PUA:Win32/Youxun also known as:

MicroWorld-eScanTrojan.GenericKD.32772148
FireEyeGeneric.mg.f063a1e88c8cee26
CAT-QuickHealTrojan.Youxun
McAfeeArtemis!F063A1E88C8C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0054b91b1 )
BitDefenderTrojan.GenericKD.32772148
K7GWRiskware ( 0054b91b1 )
Invinceaheuristic
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.32772148
Kasperskynot-a-virus:Downloader.Win32.YXdown.adk
AlibabaDownloader:Win32/YXdown.b8dbe399
Paloaltogeneric.ml
AegisLabRiskware.Win32.YXdown.1!c
Ad-AwareTrojan.GenericKD.32772148
EmsisoftTrojan.GenericKD.32772148 (B)
ComodoMalware@#xouud706p4q9
ZillyaTool.YouXun.Win32.770
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.ZHMA-8755
JiangminDownloader.YXdown.aq
WebrootW32.Malware.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F41034
ZoneAlarmnot-a-virus:Downloader.Win32.YXdown.adk
MicrosoftPUA:Win32/Youxun
AhnLab-V3PUP/Win32.Agent.R307138
ALYacTrojan.GenericKD.32772148
MAXmalware (ai score=100)
VBA32BScope.Trojan.FakeAlert
MalwarebytesRiskWare.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.L
TrendMicro-HouseCallTROJ_GEN.R004H0CL219
RisingPUA.Youxun!8.F60F (CLOUD)
YandexRiskWare.YouXun!
eGambitUnsafe.AI_Score_66%
FortinetW32/Eldorado.5AE8!tr
MaxSecureTrojan.Malware.74719855.susgen
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove PUA:Win32/Youxun?

PUA:Win32/Youxun removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment