Risk

Win32/RiskWare.YouXun.X removal guide

Malware Removal

The Win32/RiskWare.YouXun.X is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.YouXun.X virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Win32/RiskWare.YouXun.X?


File Info:

name: 0E62720EF7AC9BC5D975.mlw
path: /opt/CAPEv2/storage/binaries/671842e2782c30e0852aec08c4842949f1e423db3b474ab1a1c06e21a9924aef
crc32: A3BE3B7C
md5: 0e62720ef7ac9bc5d975443569264a51
sha1: 88dad9e884996265039bf9a31dc9451f397b81d1
sha256: 671842e2782c30e0852aec08c4842949f1e423db3b474ab1a1c06e21a9924aef
sha512: dc5be733e651f9c305ac8f3f94bee15468f1882f9bdd549b897dc219aa9099c343733e45d2aa247cefff61e4634085f21c05457e1610202cc7101234821f9643
ssdeep: 49152:1eB5p78urpIvu2JenH+gJO8KMYbLYDpWOOYUUHaBj2Ax4kn:oBMKcnenH+gJO7MCLYNWO/UUHaBj2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A959F22BB92C076C133353146CAE379B7AAEF305F35568B66800F396E34593693D61B
sha3_384: f84aa52e51fcdba433cec28fcd862a9c0731dde3e5544923686c4e5e664dce1ee7ce417d8a78e01ad1defa802ee116bf
ep_bytes: e8b08f0000e979feffff3b0dc0d95900
timestamp: 2019-08-02 03:04:36

Version Info:

FileVersion: 33.2.1.2
InternalName: RichMTip.exe
OriginalFilename: RichMTip.exe
ProductVersion: 33.2.1.2
Translation: 0x0804 0x03a8

Win32/RiskWare.YouXun.X also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Bundler.YouXun.3
FireEyeGeneric.mg.0e62720ef7ac9bc5
ALYacGen:Variant.Application.Bundler.YouXun.3
CylanceUnsafe
ZillyaTool.YouXun.Win32.701
SangforAdware.Win32.KuwanBar.gen
AlibabaRiskWare:Win32/YouXun.848653ed
Cybereasonmalicious.ef7ac9
CyrenW32/S-41c29a99!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/RiskWare.YouXun.X
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuwanBar.gen
BitDefenderGen:Variant.Application.Bundler.YouXun.3
AvastWin32:Malware-gen
TencentUw:Adware.Win32.Zusy.yb
Ad-AwareGen:Variant.Application.Bundler.YouXun.3
SophosGeneric PUA II
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKP21
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftGen:Variant.Application.Bundler.YouXun.3 (B)
GDataGen:Variant.Application.Bundler.YouXun.3
JiangminAdWare.KuwanBar.br
MAXmalware (ai score=76)
Antiy-AVLTrojan/Generic.ASMalwS.2C58C2F
ViRobotAdware.Youxun.1881600.B
MicrosoftProgram:Win32/Occamy.AA
CynetMalicious (score: 100)
McAfeeGenericRXIY-WG!0E62720EF7AC
VBA32BScope.Trojan.FakeAlert
MalwarebytesMalware.AI.2219504778
TrendMicro-HouseCallTROJ_GEN.R002C0PKP21
RisingMalware.Uwasson!8.11125 (C64:YzY0OpON4mPJIbMe)
IkarusPUA.RiskWare.Youxun
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/grayware_confidence_100% (W)
MaxSecureTrojan.Malware.79570637.susgen

How to remove Win32/RiskWare.YouXun.X?

Win32/RiskWare.YouXun.X removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment