PUA

YouXun (PUA) removal

Malware Removal

The YouXun (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What YouXun (PUA) virus can do?

  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

www.baidu.com
box.bainuonet.com
ggstats.box.bainuonet.com
tongji2.box.bainuonet.com

How to determine YouXun (PUA)?


File Info:

crc32: FDF91956
md5: 6c44841030c205c06c3e77adb472371f
name: ____________________________ip2017_15447809.exe
sha1: d179578a08cd5b3571d827f3116d80f8617050a6
sha256: ded1917560cf7d0358115c2c9b386c8696b9753902166ce3fd75f875ea9af4e3
sha512: 7f9513ae7f69f03550503d65f49cdb2d184654473f68e8bc44f1c68ca0941deef50734186bbed3588eb8a66597f68a8fbac54436ee8038e87333ef24c38f01e6
ssdeep: 196608:icz7knUlC+SoiQwFWizm6+K1glN7iW440shyptaFguCiJi:VkKCyiQKm6+KC214FhyptaFguCr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017 kunshan bainuo Information Technology
InternalName: Game Box Install Package
FileVersion: 9, 2, 6, 1
Comments: Install Guide
ProductName: Game Box Install Guide
ProductVersion: 9, 2, 6, 1
FileDescription: Game Box Install Package
OriginalFilename: installpackage.exe
Translation: 0x0804 0x04b0

YouXun (PUA) also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.31546200
FireEyeGeneric.mg.6c44841030c205c0
McAfeeGenericRXGT-GF!6C44841030C2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.Agent.1!c
K7AntiVirusRiskware ( 0050b49d1 )
BitDefenderTrojan.GenericKD.31546200
K7GWRiskware ( 0050b49d1 )
Cybereasonmalicious.030c20
TrendMicroTROJ_GEN.R002C0OLT19
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.YouXun.H
TrendMicro-HouseCallTROJ_GEN.R002C0OLT19
AvastWin32:PUP-gen [PUP]
GDataTrojan.GenericKD.31546200
Kasperskynot-a-virus:AdWare.Win32.KuwanBar.a
AlibabaRiskWare:Win32/YouXun.0aff3ba2
NANO-AntivirusRiskware.Win32.YouXun.figwkr
APEXMalicious
Ad-AwareTrojan.GenericKD.31546200
SophosYouXun (PUA)
ComodoApplicUnwnt@#2hyjol4qyxp9i
F-SecureTrojan.TR/Downloader.mlwkr
ZillyaTool.YouXun.Win32.383
Invinceaheuristic
McAfee-GW-EditionGenericRXGT-GF!6C44841030C2
EmsisoftTrojan.GenericKD.31546200 (B)
SentinelOneDFI – Suspicious PE
JiangminRiskTool.Agent.abn
eGambitUnsafe.AI_Score_87%
AviraTR/Downloader.mlwkr
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E15B58
ZoneAlarmnot-a-virus:AdWare.Win32.KuwanBar.a
MicrosoftPUA:Win32/Youxun
VBA32BScope.Backdoor.Kelihos
ALYacTrojan.GenericKD.31546200
MalwarebytesRiskWare.Agent
PandaTrj/CI.A
RisingAdware.Downloader!1.B962 (CLOUD)
YandexRiskware.Agent!
IkarusPUA.RiskWare.Youxun
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ABN!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)

How to remove YouXun (PUA)?

YouXun (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment