Risk

What is “RiskWare.YouXun”?

Malware Removal

The RiskWare.YouXun is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskWare.YouXun virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Generates some ICMP traffic

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.pcsoft.jshhdian.com
ggstats.yb.jshhdian.com
eoud.dgygpx.com
www.baidu.com
api.yb.jshhdian.com
poik.dgygpx.com
ymte.sgdebao.com

How to determine RiskWare.YouXun?


File Info:

crc32: A9EDC262
md5: d474588b16b6dae9bb292610a1d98380
name: ________________24_312.exe
sha1: afad50703e0f31f25c9af66ca8870d1717379386
sha256: 78c576acbdc310699920243bd58cf5b9249807c56906c260cd8d441e3e6b7b2b
sha512: 1ef2ac9b6364aab1d3da77a5000dea42ee5849ddd2d42336ac7ccb77faa3ccd1772266a6ac631aa41b263ae138cbb9736d95dc4b17a01bf25691a50784e3dec0
ssdeep: 98304:7djrfbWvOUlCnJ+I9P0ABLGejAMJ8C2IXDOXqHBQ+RSQnhj1Emq3v05hX6mx3o1N:dCO0E0ABLlJfCQjqX3vU3IrftzUo
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 3.0.1.2
ProductName: x6781x901fx4e0bx8f7dx5668
ProductVersion: 3.0.1.2
FileDescription: x6781x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x03a8

RiskWare.YouXun also known as:

MicroWorld-eScanTrojan.GenericKD.42284019
FireEyeGeneric.mg.d474588b16b6dae9
CAT-QuickHealPUA.IgenericRI.S10596407
Qihoo-360Win32/Virus.Downloader.b00
McAfeeGenericRXAA-AA!D474588B16B6
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0050b49d1 )
BitDefenderTrojan.GenericKD.42284019
Cybereasonmalicious.03e0f3
BitDefenderThetaGen:NN.ZexaF.34084.@pLfaqRCqwnj
F-ProtW32/S-d8efc1c1!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.42284019
Kasperskynot-a-virus:HEUR:Downloader.Win32.YXdown.pef
Ad-AwareTrojan.GenericKD.42284019
EmsisoftTrojan.GenericKD.42284019 (B)
F-SecurePrivacyRisk.SPR/GameTool.Gen8
ZillyaTool.YouXun.Win32.803
McAfee-GW-EditionBehavesLike.Win32.Multiplug.rc
Trapminesuspicious.low.ml.score
IkarusPUA.RiskWare.Youxun
CyrenW32/S-d8efc1c1!Eldorado
JiangminDownloader.YXdown.bz
AviraSPR/GameTool.Gen8
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D28533F3
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.YXdown.pef
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Malware/Win32.Generic.C3974891
ALYacTrojan.GenericKD.42284019
MAXmalware (ai score=82)
VBA32Downloader.YXdown
MalwarebytesRiskWare.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.H
RisingAdware.Downloader!1.B962 (RDMK:cmRtazqNJNepVcp8MfFXEqb69QTV)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenericKD.32784984!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.74721109.susgen

How to remove RiskWare.YouXun?

RiskWare.YouXun removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment