Trojan

Trojan.Heur.YmLfX8a6tefc malicious file

Malware Removal

The Trojan.Heur.YmLfX8a6tefc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.YmLfX8a6tefc virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Trojan.Heur.YmLfX8a6tefc?


File Info:

crc32: AD76B3B3
md5: ff07d19b1d31e0575c9655c90a8abac8
name: FF07D19B1D31E0575C9655C90A8ABAC8.mlw
sha1: 8b805bbb6180918bafee5852e8889e0224d28ae1
sha256: 5de7c8e00dfaa62756c704dcd0d3ede2f7f6d19f3c51e12442ea7d95648a276d
sha512: f32e5d00a2527d3c72fe8e9ba4d832cde565f269fa667d64990ce4fa70f1d6729b608de225c50ae7cf0c766bf5094be9e5f5714aa84b0b3d7e551601ad637b7f
ssdeep: 12288:cA0wAthYBpP0gvqit1zAgVCLeL32+2dy9EyHOnpn5V1x/0/AvHKJCROmHoS:cANzUit1VCLK12dyyqOn7zxM/AP5Om
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: CSRSS.Exe
FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.3.9600.16384
FileDescription: Client Server Runtime Process
OriginalFilename: CSRSS.Exe
Translation: 0x0409 0x04b0

Trojan.Heur.YmLfX8a6tefc also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b8aa51 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.YmLfX8a6tefc
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5790
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.b1d31e
BaiduWin32.Trojan.FileCoder.b
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Shade.B
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Troldesh-7357571-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.YmLfX8a6tefc
MicroWorld-eScanGen:Trojan.Heur.YmLfX8a6tefc
Ad-AwareGen:Trojan.Heur.YmLfX8a6tefc
SophosML/PE-A + Mal/Troldesh-A
BitDefenderThetaAI:Packer.C7BFEF021C
McAfee-GW-EditionBehavesLike.Win32.Fake.cc
FireEyeGeneric.mg.ff07d19b1d31e057
EmsisoftGen:Trojan.Heur.YmLfX8a6tefc (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.gdezo
AviraTR/Crypt.FKM.Gen
eGambitUnsafe.AI_Score_95%
ArcabitTrojan.Heur.YmLfX8a6tefc
GDataGen:Trojan.Heur.YmLfX8a6tefc
AhnLab-V3Trojan/Win32.Generic.C1566003
MAXmalware (ai score=89)
VBA32SScope.Malware-Cryptor.Filecoder
MalwarebytesTrojan.FakeMS
RisingRansom.Troldesh!8.5D1 (RDMK:cmRtazrDpok8lxF5k3tn/ppy53PH)
YandexTrojan.GenAsa!Lu8cdcqmYJU
IkarusTrojan-Ransom.Troldesh
FortinetW32/Troldesh.71B6!tr.ransom
AVGFileRepMalware
Qihoo-360HEUR/QVM18.1.0A1B.Malware.Gen

How to remove Trojan.Heur.YmLfX8a6tefc?

Trojan.Heur.YmLfX8a6tefc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment