Trojan

Trojan.Heur.RP.ymGfb0nchRdb removal instruction

Malware Removal

The Trojan.Heur.RP.ymGfb0nchRdb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.RP.ymGfb0nchRdb virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Heur.RP.ymGfb0nchRdb?


File Info:

name: 4A5CFE3E588D765C4A61.mlw
path: /opt/CAPEv2/storage/binaries/cf67d13972a287eb23a02f00f7dce1c84b3b59a877adf2a0ff4d8297d1201582
crc32: 7C290EE2
md5: 4a5cfe3e588d765c4a61a9919088395f
sha1: 0bf10cd6a8319f6379c2241a0e7ff0c466e30c68
sha256: cf67d13972a287eb23a02f00f7dce1c84b3b59a877adf2a0ff4d8297d1201582
sha512: f1f37f4c427fe1b74849b142017aa7f8c67cd137f06b60ab2a764731ee1ed24ae945db0bae6d43fe41aa4ff5a56d81db493d60bdb8801c77cb8cb8a46c9e5a40
ssdeep: 6144:Nk9g0RWjqbtSkSAp81xiNGcuR8hnpY1iAwJ4gkFJqYURkhZYXMpL/wS:NkCuWjotSkScBdxpY1iX8z4RkhZYgL4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185842377200124B5F563043DA92CB4D51D0A5EC34B3E68C90E1ADED439BB5DBBA8A3E9
sha3_384: 4a636dcbf96beb6ebb2885d1b7f025a726226b0b1e87fde24bcaec9fa1c93fcc7175ad59371f20ffd4da7fccb1a17747
ep_bytes: 60be007041008dbe00a0feff5783cdff
timestamp: 2014-12-17 06:56:42

Version Info:

0: [No Data]

Trojan.Heur.RP.ymGfb0nchRdb also known as:

LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur.RP.ymGfb0nchRdb
FireEyeGeneric.mg.4a5cfe3e588d765c
McAfeeArtemis!4A5CFE3E588D
CylanceUnsafe
VIPREGen:Trojan.Heur.RP.ymGfb0nchRdb
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Downloader.Y.gen!Eldorado
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.ttam
BitDefenderGen:Trojan.Heur.RP.ymGfb0nchRdb
NANO-AntivirusTrojan.Win32.Inject.dlldbu
AvastWin32:Malware-gen
TencentWin32.Trojan.Hijacker.Ocnw
Ad-AwareGen:Trojan.Heur.RP.ymGfb0nchRdb
SophosMal/Behav-027
F-SecureTrojan.TR/Hijacker.Gen
DrWebTrojan.DownLoader12.11306
ZillyaTrojan.Inject.Win32.161747
TrendMicroTROJ_GEN.R067C0PJ222
McAfee-GW-EditionBehavesLike.Win32.Ipamor.fc
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.RP.ymGfb0nchRdb (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Hijacker.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Heur.RP.ymGfb0nchRdb
ZoneAlarmTrojan.Win32.Inject.ttam
GDataGen:Trojan.Heur.RP.ymGfb0nchRdb
GoogleDetected
BitDefenderThetaAI:Packer.3ECD49921F
ALYacGen:Trojan.Heur.RP.ymGfb0nchRdb
MAXmalware (ai score=85)
VBA32Trojan.Inject
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R067C0PJ222
YandexTrojan.Inject!zqTZmfuNwT0
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Inject.TTAM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Trojan.Heur.RP.ymGfb0nchRdb?

Trojan.Heur.RP.ymGfb0nchRdb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment