Malware

Should I remove “Troj/DwnLdr-YLF”?

Malware Removal

The Troj/DwnLdr-YLF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/DwnLdr-YLF virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Slovak
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/DwnLdr-YLF?


File Info:

name: 8A74D531FA839CAF056A.mlw
path: /opt/CAPEv2/storage/binaries/de0501b0dec624b7f496628b0d7c76cc8a6308aa38c7358adfefe3e9eb49a7e0
crc32: 7A517C4C
md5: 8a74d531fa839caf056a7a9c24237cd7
sha1: 746081c40128fe5b097bfc9930b6c9b5ae560888
sha256: de0501b0dec624b7f496628b0d7c76cc8a6308aa38c7358adfefe3e9eb49a7e0
sha512: fde6e706f99beeb21674a86c932b85c69621393247395c47db6da033c881c4cae6ccf021eddbb86d776011dcd87c0212737b02a1b65faebd1245b7ba823643f3
ssdeep: 3072:COQRk4Um06ZL66Ai7O9SXw5b9Z+mShDihIQsEJn6S833dk/z:rp4UK/A54g5brRwhQVnuHd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123F38C0236D0C073E4BE06725DA58A12762DFCB51B606AF73388127D1AB26D15E36F5E
sha3_384: 45e06c0de9b37c12d9ec4ec3c613d37e8500be594560c768db8af36cade30e503aff74815e43ae8cf5e9f8a1d9765ff8
ep_bytes: 558bec81ec70090000e8b20c00008985
timestamp: 1970-01-01 15:50:05

Version Info:

FileVersion: 1.0.5.4
InternalName: fyukfuyk.exe
LegalCopyright: Copyright (C) 2019, ghjhfkh
ProductVersion: 1.7.6
Translation: 0x0841 0x04c4

Troj/DwnLdr-YLF also known as:

BkavW32.SmallzerotND.PE
LionicTrojan.Win32.PornoBlocker.tqLZ
tehtrisGeneric.Malware
DrWebTrojan.MulDrop4.25343
MicroWorld-eScanGen:Variant.Ransom.GandCrab.2689
SkyhighBehavesLike.Win32.Corrupt.ch
McAfeeGenericRXID-XJ!8A74D531FA83
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 0055485e1 )
AlibabaTrojanDownloader:Win32/DwnLdr.6653622a
K7GWTrojan-Downloader ( 00552ecf1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36680.ky0@auQdjUgG
VirITWin32.Nov15th.A
SymantecInfostealer
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.EQH
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Patched.rw
BitDefenderGen:Variant.Ransom.GandCrab.2689
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DeadZero [Inf]
RisingVirus.Phorpiex!1.E9B1 (CLASSIC)
SophosTroj/DwnLdr-YLF
F-SecureMalware.W32/Infector.Gen
VIPREGen:Variant.Ransom.GandCrab.2689
TrendMicroTrojanSpy.Win32.FICKERSTEALER.SMTHA.hp
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.bdga
WebrootW32.Trojan.Gen
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLTrojan[Downloader]/Win32.Agent.a
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/SmallAgent!atmn
XcitiumTrojWare.Win32.TrojanDownloader.Bandit.C@8cwa34
ArcabitTrojan.Ransom.GandCrab.DA81
ViRobotTrojan.Win32.S.Agent.171008.GN
ZoneAlarmTrojan.Win32.Patched.rw
GDataWin32.Trojan.PSE.11JDK9U
VaristW32/Agent_Troj.J.gen!Eldorado
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
VBA32BScope.TrojanBanker.CliptoShuffler
TACHYONWorm/W32.ZeroDownloader
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaGeneric Suspicious
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTrojanSpy.Win32.FICKERSTEALER.SMTHA.hp
TencentVirus.Win32.Patched.kh
IkarusTrojan.Krypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Agent.EQH!tr
AVGWin32:DeadZero [Inf]
Cybereasonmalicious.40128f
DeepInstinctMALICIOUS

How to remove Troj/DwnLdr-YLF?

Troj/DwnLdr-YLF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment