Trojan

MemScan:Trojan.Dropper.YRL removal instruction

Malware Removal

The MemScan:Trojan.Dropper.YRL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Dropper.YRL virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine MemScan:Trojan.Dropper.YRL?


File Info:

crc32: 3F037C70
md5: 21ccaef3d057c612ad68af79bff71c01
name: 21CCAEF3D057C612AD68AF79BFF71C01.mlw
sha1: 26fe6278837150f0cadf2166e792dcd533aca2b9
sha256: b68c19a8cb250df12f5f7a9a8a6a7950fcf13db08521aef7f1db0d4fe07d0ce3
sha512: 775a3f215f09c2ec8756d814a953d1d46d7fd3cd63aa669158821305921c3a3d6dd0b202c745c5dda9f42e56622049c9572e2a3a495f68b37b08288d81a9f923
ssdeep: 1536:cAhTyTTFQNC13U4rtnDb4tmJtwPT9KGjkLkNAsaEk:BhT2137DYmJtw7fuFX
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

MemScan:Trojan.Dropper.YRL also known as:

K7AntiVirusTrojan ( 0046c2461 )
LionicTrojan.Win32.Generic.l4OI
Elasticmalicious (high confidence)
DrWebBackDoor.Spy.2437
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Farfli.33028
ALYacMemScan:Trojan.Dropper.YRL
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Zegost.e
K7GWTrojan ( 0046c2461 )
Cybereasonmalicious.3d057c
BaiduWin32.Trojan.Agent.atj
CyrenW32/Trojan.ANWT-7143
SymantecSMG.Heur!gen
ESET-NOD32Win32/Agent.QID
ZonerTrojan.Win32.28054
APEXMalicious
AvastWin32:Dropper-ODE [Drp]
ClamAVWin.Trojan.Farfli-9829623-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderMemScan:Trojan.Dropper.YRL
NANO-AntivirusTrojan.Win32.Farfli.dbsqsq
MicroWorld-eScanMemScan:Trojan.Dropper.YRL
TencentWin32.Trojan.Staser.Hqvs
Ad-AwareMemScan:Trojan.Dropper.YRL
ComodoBackdoor.Win32.Farfli.AC@77g02n
BitDefenderThetaAI:Packer.3518E8ED1F
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SM40
McAfee-GW-EditionBehavesLike.Win32.Dropper.qc
FireEyeGeneric.mg.21ccaef3d057c612
EmsisoftMemScan:Trojan.Dropper.YRL (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Farfli.iw
AviraTR/Beaugrit.aba
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.246F
KingsoftWin32.Hack.Farfli.h.(kcloud)
MicrosoftBackdoor:Win32/Zegost.CD!bit
ArcabitTrojan.Dropper.YRL
GDataMemScan:Trojan.Dropper.YRL
McAfeeArtemis!21CCAEF3D057
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesBackdoor.Farfli
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.SM40
RisingBackdoor.Fusing!1.BCB6 (CLASSIC)
YandexBackdoor.Farfli!v+/omUPj8WE
IkarusBackdoor.Win32.Farfli
FortinetW32/Agent.QRW!tr
AVGWin32:Dropper-ODE [Drp]
Paloaltogeneric.ml

How to remove MemScan:Trojan.Dropper.YRL?

MemScan:Trojan.Dropper.YRL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment