Risk

Win32/RiskWare.YouXun.Z malicious file

Malware Removal

The Win32/RiskWare.YouXun.Z is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RiskWare.YouXun.Z virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity contains more than one unique useragent.

Related domains:

api.pcsoft.jshhdian.com
ggstats.yb.jshhdian.com
dw.jshhdian.com
api.pcsoft.70gj.cn

How to determine Win32/RiskWare.YouXun.Z?


File Info:

crc32: ADC21D04
md5: ffe8eedf9508a72743bac1effdd7fd22
name: _______________-google-chrome_24_206.exe
sha1: 9394f16250edff1c4231d9b2932987cd0985cabc
sha256: 5957c5de979484c7f2d16242a34bdf87c8c2ff6ac2e9484b799ca6c8488f118f
sha512: ed8a9c0cf720f7d337b544c0a819ee0b7f9356e7dd2f9988ffe2194604816fd05b9c7a12540e5f8295074ba6edae92eff44563fad1016162be7823c03fdb3996
ssdeep: 98304:7djrfbWvOUlCnJ+I9P0ABLGejAMJ8C2IXDOXqHBQ+RSQnhj1Emq3v05hX6mx3o19:dCO0E0ABLlJfCQjqX3vU3IrftzUo
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 3.0.1.2
ProductName: x6781x901fx4e0bx8f7dx5668
ProductVersion: 3.0.1.2
FileDescription: x6781x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x03a8

Win32/RiskWare.YouXun.Z also known as:

MicroWorld-eScanTrojan.GenericKD.42284019
CAT-QuickHealPUA.IgenericRI.S10596407
Qihoo-360HEUR/QVM11.1.1AAD.Malware.Gen
McAfeeGenericRXAA-AA!FFE8EEDF9508
ZillyaTool.YouXun.Win32.803
SangforMalware
K7AntiVirusRiskware ( 0050b49d1 )
BitDefenderTrojan.GenericKD.42284019
K7GWRiskware ( 0050b49d1 )
Cybereasonmalicious.250edf
F-ProtW32/S-d8efc1c1!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.42284019
Kasperskynot-a-virus:AdWare.Win32.KuwanBar.a
AvastWin32:Malware-gen
RisingAdware.Downloader!1.B962 (RDMK:cmRtazqNJNepVcp8MfFXEqb69QTV)
Ad-AwareTrojan.GenericKD.42284019
F-SecurePrivacyRisk.SPR/GameTool.Gen8
DrWebAdware.Youxun.1
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.ffe8eedf9508a727
EmsisoftTrojan.GenericKD.42284019 (B)
IkarusPUA.RiskWare.Youxun
CyrenW32/S-d8efc1c1!Eldorado
JiangminDownloader.YXdown.bz
AviraSPR/GameTool.Gen8
Antiy-AVLRiskWare[Downloader]/Win32.YXdown
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D28533F3
ZoneAlarmnot-a-virus:AdWare.Win32.KuwanBar.a
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Malware/Win32.Generic.C3974891
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34100.@pLfaqRCqwnj
ALYacTrojan.GenericKD.42284019
MAXmalware (ai score=82)
VBA32Downloader.YXdown
MalwarebytesRiskWare.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.Z
YandexPUA.Downloader!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenericKD.32784984!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.74721109.susgen

How to remove Win32/RiskWare.YouXun.Z?

Win32/RiskWare.YouXun.Z removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment