Trojan

Trojan.PWS.YVM (file analysis)

Malware Removal

The Trojan.PWS.YVM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.PWS.YVM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 0.0.0.0:29254, :0
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristics of BlackRemote/BlackRAT RAT
  • Creates a hidden or system file
  • Attempts to modify browser security settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Clears web history

How to determine Trojan.PWS.YVM?


File Info:

name: CE6622FB61BA5573706D.mlw
path: /opt/CAPEv2/storage/binaries/126f591353ad7e1a4b4d06661f7de7d3f4fa5aa5d238d55e3ce041e734080ce4
crc32: 3B0A1201
md5: ce6622fb61ba5573706df029622b8164
sha1: 099ba188a2f293232c2ee68837a93f4ad78484fe
sha256: 126f591353ad7e1a4b4d06661f7de7d3f4fa5aa5d238d55e3ce041e734080ce4
sha512: dd534d764b0ff28df0791b026dca51bc6e0f1ee70c6e681134240d32c65f305b68267550766130da1a85e80f1574098d40fbff50ca8c2950985651d9ae07c293
ssdeep: 6144:80+N1vgAwzqEybL8eXiqLnFHxua12BM6SZMIEPlil/M5:PSCAXJ8exLuo6MCPlil/M5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B54F182BA1D8F87C5B412B0009AA30200ADBADEBC5BD16A5E5CA34DF47D4D185FF76D
sha3_384: 2e5e0233c01f58e5eb000553bdce0b25c01e99caa836f814fb712ad833f2d8fc08b21dd9becaff89475dc1c1a7e18c87
ep_bytes: 558bec81eccc02000060892d647f4400
timestamp: 2012-04-11 03:20:21

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Disk Diagnostic User Resolver
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: DFDWiz.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: DFDWiz.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Trojan.PWS.YVM also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lw2L
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.PWS.YVM
FireEyeGeneric.mg.ce6622fb61ba5573
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeePWS-Zbot.gen.bew
CylanceUnsafe
VIPRETrojan.Win32.Reveton.ca (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f02a1 )
AlibabaTrojanPSW:Win32/Kryptik.c92b12da
K7GWTrojan ( 0040f02a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Adware.Kryptik.b
VirITTrojan.Win32.Banker.HM
CyrenW32/Zbot.DQ.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Zbot.AAN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-1326
KasperskyPacked.Win32.Krap.iu
BitDefenderTrojan.PWS.YVM
NANO-AntivirusTrojan.Win32.Krap.brahfv
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Karagany
TencentMalware.Win32.Gencirc.10b7752a
Ad-AwareTrojan.PWS.YVM
TACHYONTrojan/W32.Yakes.301096
EmsisoftTrojan.PWS.YVM (B)
ComodoTrojWare.Win32.Kryptik.ADXK@4nyoqo
DrWebTrojan.PWS.Panda.2004
ZillyaTrojan.Zbot.Win32.101727
TrendMicroMal_Ransom-1
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Troj/Zbot-DHN
IkarusTrojan-Spy.Win32.Zbot
GDataTrojan.PWS.YVM
JiangminTrojanSpy.Zbot.bpyw
AviraTR/Spy.Zbot.ZP.6
Antiy-AVLTrojan/Generic.ASMalwS.AB6
ArcabitTrojan.PWS.YVM
ViRobotTrojan.Win32.A.Zbot.280759
ZoneAlarmPacked.Win32.Krap.iu
MicrosoftPWS:Win32/Zbot.gen!AF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R23747
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.sq1@amhFhtli
ALYacTrojan.PWS.YVM
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Panda
MalwarebytesMalware.AI.1372763556
TrendMicro-HouseCallMal_Ransom-1
RisingSpyware.Zbot!8.16B (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Packed.Krap.iu
FortinetW32/ZBOT.HL!tr
WebrootW32.Rogue.Gen
AVGWin32:Karagany
Cybereasonmalicious.b61ba5
PandaBck/Qbot.AO

How to remove Trojan.PWS.YVM?

Trojan.PWS.YVM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment