Risk

How to remove “YouXun.Riskware.Agent.DDS”?

Malware Removal

The YouXun.Riskware.Agent.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What YouXun.Riskware.Agent.DDS virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine YouXun.Riskware.Agent.DDS?


File Info:

name: B70DA4C5C260856585C6.mlw
path: /opt/CAPEv2/storage/binaries/2ffc043b3432fd125c5c5b3c38244f9982fcc80a5c6c7a53f3b03c7632f49d28
crc32: D1B90E9A
md5: b70da4c5c260856585c611fc75af02c9
sha1: cb5c9a638bfe7e7bb2a7aef2d427ef3c70d4b306
sha256: 2ffc043b3432fd125c5c5b3c38244f9982fcc80a5c6c7a53f3b03c7632f49d28
sha512: 006cccc25f362047ec9e0d747a86a1ddceb9db944d5000f3071b60ed7de58257e6c9815f765a61ae9edfe6a1830a5ffe935e5836a2a44f28df6f3415daccced1
ssdeep: 24576:0leXVJjzVC+7cSPe+3yokryFs1C06bCT+BopI/+jqEOriDKA:y6JWSW+3yomyIT+nWqEOriDKA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A55BF10B7D1E436EAB31576497EE6295169B9310B214ACBB3CC1E2E4F307D1AE3634B
sha3_384: 7030ad26405a1470f21d09889719c6ae531877e7dc3735fb994965978672340e3874c48f6621ddcd1a5a84e12961170f
ep_bytes: e8fa9e0000e979feffff3b0d50794e00
timestamp: 2018-03-12 12:24:11

Version Info:

Comments: 游戏启动器
CompanyName: www.yxdown.com
FileDescription: 游迅网启动客户端
FileVersion: 5, 0, 1, 6
InternalName: GameStar.exe
LegalCopyright: 2016-2017(C)游迅网。保留所有权利
OriginalFilename: GameStar.exe
ProductName: 游迅网启动客户端
ProductVersion: 5, 0, 1, 6
Translation: 0x0804 0x04b0

YouXun.Riskware.Agent.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Adload.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68994313
FireEyeGeneric.mg.b70da4c5c2608565
MalwarebytesYouXun.Riskware.Agent.DDS
ZillyaTool.YouXun.Win32.301
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0050b49d1 )
AlibabaDownloader:Win32/YXdown.03d0eca4
K7GWRiskware ( 0050b49d1 )
CyrenW32/YouXun.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.YouXun.H
APEXMalicious
KasperskyUDS:Trojan-Downloader.Win32.Adload.gen
BitDefenderTrojan.GenericKD.68994313
NANO-AntivirusTrojan.Win32.Adload.fmvops
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b2fdd9
EmsisoftTrojan.GenericKD.68994313 (B)
F-SecurePrivacyRisk.SPR/GameTool.Gen8
VIPRETrojan.GenericKD.68994313
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.68994313
JiangminTrojanDownloader.Adload.ylo
AviraSPR/GameTool.Gen8
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Generic.D41CC509
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
McAfeeGenericRXFP-NP!B70DA4C5C260
MAXmalware (ai score=84)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CHS23
RisingAdware.YouXun!1.D190 (CLASSIC)
IkarusPUA.RiskWare.Youxun
MaxSecureTrojan.Malware.73418002.susgen
FortinetRiskware/YouXun
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove YouXun.Riskware.Agent.DDS?

YouXun.Riskware.Agent.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment