Risk

Win32/RiskWare.YouXun.AE removal

Malware Removal

The Win32/RiskWare.YouXun.AE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.YouXun.AE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/RiskWare.YouXun.AE?


File Info:

name: 5BDFB791F19FCE02FA9C.mlw
path: /opt/CAPEv2/storage/binaries/896bb9e100f7f1f8b722c2e4b799626fcb04e2a4a2f21e8d00e42ceaf059c62d
crc32: C671294B
md5: 5bdfb791f19fce02fa9c36a4f29bd406
sha1: abfa02605e3e20047b2354d50132afae98e6b373
sha256: 896bb9e100f7f1f8b722c2e4b799626fcb04e2a4a2f21e8d00e42ceaf059c62d
sha512: b191aa0b40eee8aabb91762d43dc594a8151e2929e1a45d00883460041caf8fd309793568cd764eacc4fae8b8242d76b2f247a4c5582e201c7388a4384556ac8
ssdeep: 196608:zrysgd1HBLrVIXqIuFmPGEjnCjbCGPW+BssqYNaDhw5NhdSvKulX3hNhmnkUpOYm:zrjgdzrVIXqIuFSCjTcsqcaDImxlX7hL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110B63316659593F5FD92AC35091BB0E4648C3C2B7C8930A80F96DAB96C37DC3CAC6E47
sha3_384: eb5ab63a78f44f678aa7abc3d792d2775d298bb1100ef9b350e008b42d13cb26ca166a8cc25f008f3847b862fc9f5627
ep_bytes: 60be00c05c008dbe0050e3ffc787a0ef
timestamp: 2021-12-04 08:52:23

Version Info:

Comments:
CompanyName: Install Assist
FileDescription: Ms-Zip Install Assistant
FileVersion: 8.5.1.5
InternalName: MsZipInstall.exe
LegalCopyright: Copyright (c) 2021 Ms-Zip
OriginalFilename: MsZipInstall.exe.exe
ProductName: MsZipInstall.exe
ProductVersion: 8.5.1.5
Translation: 0x0804 0x04b0

Win32/RiskWare.YouXun.AE also known as:

LionicRiskware.Win32.YXdown.1!c
MicroWorld-eScanGen:Variant.Razy.862401
FireEyeGen:Variant.Razy.862401
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Razy.862401
CylanceUnsafe
K7AntiVirusRiskware ( 005883931 )
AlibabaAdWare:Win32/YouXun.102d
K7GWRiskware ( 005883931 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.YouXun.AE
TrendMicro-HouseCallTROJ_GEN.R067H0CL821
Paloaltogeneric.ml
ClamAVWin.Malware.Roxer-9787868-0
Kasperskynot-a-virus:Downloader.Win32.YXdown.bet
BitDefenderGen:Variant.Razy.862401
NANO-AntivirusTrojan.Win32.YXdown.jiowpp
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.862401
SophosGeneric PUA KL (PUA)
DrWebTrojan.Siggen15.62317
McAfee-GW-EditionArtemis!Trojan
GDataGen:Variant.Razy.862401
JiangminDownloader.YXdown.gd
eGambitUnsafe.AI_Score_100%
MAXmalware (ai score=88)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!5BDFB791F19F
VBA32BScope.Trojan.FakeAlert
MalwarebytesMalware.AI.3766837393
IkarusTrojan.Win32
RisingAdware.Agent!1.D4E5 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetRiskware/YouXun
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/RiskWare.YouXun.AE?

Win32/RiskWare.YouXun.AE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment