PUA

PUP.Optional.YouXun removal

Malware Removal

The PUP.Optional.YouXun is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUP.Optional.YouXun virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

ggstats.box.bainuonet.com
tongji2.box.bainuonet.com
box.bainuonet.com

How to determine PUP.Optional.YouXun?


File Info:

crc32: 3794A97C
md5: f7d68b7525a3140a5d46a44f0401cf10
name: _____________________________________22364740.exe
sha1: 44f47f01ead38388d0603d86bfbc8a40cbf59653
sha256: 3c25b499f7417b0af10dcdb3a6d27d6f81fd46c64363df0dabad7a8f627debac
sha512: 773210059dc2e0878968a29342f63520e561ceb51197d9717fdec3b2b0e27bd5f2267912f79b711678d4a154045b12d41eca0a7e94414b3ac142ac54a86628d4
ssdeep: 49152:l6L3xgQ4VcWbuNAfEdHnrT3Ae/nv/xXFTQqTZO6GHwImDrQvW1K/lEknzsRpZ8uq:EL3qiNAcdHbv5FUrPmfQuAjsmu7HwUiZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017 kunshan bainuo Information Technology
InternalName: yxyxbox
FileVersion: 9, 0, 6, 6
Comments: x5b89x88c5x5411x5bfc
ProductName: x4e50x6e38x6e38x620fx5b89x88c5x5305
ProductVersion: 9, 0, 6, 6
FileDescription: x4e50x6e38x6e38x620fx5b89x88c5x7a0bx5e8fx5305
OriginalFilename: yxyxbox.exe
Translation: 0x0804 0x04b0

PUP.Optional.YouXun also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.31621644
FireEyeGeneric.mg.f7d68b7525a3140a
CAT-QuickHealTrojan.MauvaiseRI.S5255051
McAfeeGenericRXGJ-TG!F7D68B7525A3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 00502b2a1 )
BitDefenderTrojan.GenericKD.31621644
K7GWUnwanted-Program ( 00502b2a1 )
Cybereasonmalicious.525a31
Invinceaheuristic
CyrenW32/S-0476c9d0!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallHT_YOUXUN_GH010620.UVPM
GDataTrojan.GenericKD.31621644
Kasperskynot-a-virus:Downloader.Win32.Agent.kops
AlibabaRiskWare:Win32/YouXun.aa9c5cf5
NANO-AntivirusRiskware.Win32.YouXun.fhnjnl
ViRobotAdware.Graftor.4026472
APEXMalicious
Ad-AwareTrojan.GenericKD.31621644
SophosYouXun (PUA)
ZillyaAdware.YouXunCRTD.Win32.5326
TrendMicroHT_YOUXUN_GH010620.UVPM
McAfee-GW-EditionGenericRXGJ-TG!F7D68B7525A3
EmsisoftTrojan.GenericKD.31621644 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-0476c9d0!Eldorado
JiangminDownloader.Agent.gjm
MaxSecureTrojan.Malware.10837516.susgen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E2820C
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.kops
MicrosoftPUA:Win32/Youxun
VBA32Downloader.Agent
MalwarebytesPUP.Optional.YouXun
PandaPUP/Generic
ESET-NOD32a variant of Win32/RiskWare.YouXun.B
RisingMalware.Heuristic!ET#100% (C64:YzY0Ong1E0JpBJoI)
YandexRiskWare.YouXun!
IkarusPUA.RiskWare.Youxun
eGambitGeneric.Malware
FortinetRiskware/YouXun
WebrootW32.Trojan.Gen
AVGFileRepMetagen [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove PUP.Optional.YouXun?

PUP.Optional.YouXun removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment