Backdoor

Backdoor:Win32/Yonsole.B information

Malware Removal

The Backdoor:Win32/Yonsole.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Yonsole.B virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)

How to determine Backdoor:Win32/Yonsole.B?


File Info:

crc32: 9E67A264
md5: 4cc8106221df9c134c3a3607e8696bbd
name: 4CC8106221DF9C134C3A3607E8696BBD.mlw
sha1: 60b7fc18106beb71016f586ba13940adb6895774
sha256: 8fd8a4cbc2814f97edf37b98bc7d21fc17d008ab49642d0e17f9c5e92aefa732
sha512: 5f965735bf144bb754ab824882717c36d5fca04ea296f1eb46b7e39d3c4ae477428e87514e517cc51865ea83a19c9ac54645712264593b92c84c8538879e19e8
ssdeep: 1536:xJ0cjtqTgpdJEHlwKg2cxhDfiJ8Xm3oBJIZsiZ3P4IL:NjtwaPBKg2ihjiJ8W3oBJIfZ3P
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ? Microsoft Corporation. All rights reserved.
InternalName: Microsoft DirectMusic Scripting
FileVersion: 5.3.2600.5512 (xpsp.080413-0845)
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft(R) Windows(R) Operating System
SpecialBuild:
ProductVersion: 5.3.2600.5512
FileDescription: Microsoft DirectMusic Scripting
OriginalFilename: dmscript.dll
Translation: 0x0409 0x04b0

Backdoor:Win32/Yonsole.B also known as:

TotalDefenseWin32/Torr.B!genus
MicroWorld-eScanBackdoor.Generic.639793
nProtectBackdoor/W32.Torr.100352.G
McAfeePWS-OnlineGames.im
MalwarebytesSpyware.OnlineGames
K7AntiVirusPassword-Stealer
K7GWBackdoor
TheHackerBackdoor/Torr.cit
NANO-AntivirusTrojan.Win32.Torr.bnzwj
F-ProtW32/OnlineGames.EI.gen!Eldorado
SymantecInfostealer
NormanYonsole.D
TrendMicro-HouseCallMal_PClient
AvastWin32:Yonsole [Trj]
ClamAVTrojan.Agent-208622
KasperskyBackdoor.Win32.Torr.cti
BitDefenderBackdoor.Generic.639793
AgnitumBackdoor.Torr.Gen
ViRobotBackdoor.Win32.A.Torr.99840
SophosTroj/Inject-MZ
ComodoBackdoor.Win32.Torr.~FK
F-SecureBackdoor.Generic.639793
DrWebBackDoor.Bull
VIPREBackdoor.Win32.Yonsole.b (v)
AntiVirTR/Spy.Gen
TrendMicroMal_PClient
McAfee-GW-EditionPWS-OnlineGames.im
EmsisoftBackdoor.Generic.639793 (B)
JiangminBackdoor/Agent.cwrd
KingsoftWin32.Troj.FakeMS.uu.(kcloud)
MicrosoftBackdoor:Win32/Yonsole.B
SUPERAntiSpywareTrojan.Agent/Gen-Farfli
GDataBackdoor.Generic.639793
CommtouchW32/OnlineGames.EI.gen!Eldorado
AhnLab-V3Backdoor/Win32.Torr
VBA32Backdoor.Torr
PCToolsTrojan-PSW.Generic!rem
ESET-NOD32a variant of Win32/Farfli.AK
RisingBackdoor.Win32.Undef.gqz
IkarusBackdoor.Win32.Yonsole
FortinetW32/Magania.EPAB!tr
AVGWorm/Generic.BHMS
PandaBck/Torr.A

How to remove Backdoor:Win32/Yonsole.B?

Backdoor:Win32/Yonsole.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment