Crack Trojan

Should I remove “Generic.Trojan.PatchedPE.DDS”?

Malware Removal

The Generic.Trojan.PatchedPE.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Trojan.PatchedPE.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Trojan.PatchedPE.DDS?


File Info:

name: 3D85E9D8F2C0FFDD63C0.mlw
path: /opt/CAPEv2/storage/binaries/7245e10912c62a52c612431c779d9708e11d25dd7625d241eed1d999e7fd9d34
crc32: 7304132C
md5: 3d85e9d8f2c0ffdd63c0f1463f92b47a
sha1: 14a59bdfe1b69384e5ff58b359d436ac81845c1f
sha256: 7245e10912c62a52c612431c779d9708e11d25dd7625d241eed1d999e7fd9d34
sha512: 190d35f51cf258c0a3458ab2a91cd295bbb2590e7f8b641c4edd8633856a4517f70697777ca3c19f2ba1242aebce4acf4e4f7e1aafd3fdbf47ea8d15decb3d33
ssdeep: 12288:+QQPuq4zGk02X49/H05yyTpNjrQlAwVlAwL2pa5HsaX6:Euq8X4FH0MyTpNjMlhl/Hs+6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5053960BA93A623C493D23C6F25C19A58261D11075284E363D47E2E3E749F17AF1FEE
sha3_384: a7ebe05a645341a0c8a22e07c2ba675e6ff81bacf449cc7b6d0dc21d10afc91017cd3eb61a0fbfbf36821846a4056e79
ep_bytes: e8b3050000e98efeffffff25b0824400
timestamp: 2017-12-04 10:10:09

Version Info:

CompanyName: iQIYI.COM
FileDescription: IQIYI Video Helper
FileVersion: 15.0.1.589
InternalName: QyKernel.exe
LegalCopyright: Copyright (C) 2016 - All Rights Reserved
OriginalFilename: QyKernel.exe
ProductName: IQIYI Video Helper
ProductVersion: 15.0.1.589
Translation: 0x0804 0x04b0

Generic.Trojan.PatchedPE.DDS also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ExplorerHijack.Z82@ayN!zBoj
FireEyeGeneric.mg.3d85e9d8f2c0ffdd
McAfeePacked-FAQ!3D85E9D8F2C0
Cylanceunsafe
ZillyaTrojan.Patched.Win32.124231
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0015dce31 )
K7GWTrojan ( 0015dce31 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36132.Z82@ayN!zBoj
CyrenW32/Patched.GB.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Agent.NFN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Processhijack-9842321-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ExplorerHijack.Z82@ayN!zBoj
NANO-AntivirusTrojan.Win32.Patched.eyztvm
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:Evo-gen [Trj]
TencentWin32.Virus.Agent.Kqil
SophosTroj/Patched-BS
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.HLLP.Siggen.54
VIPREGen:Trojan.ExplorerHijack.Z82@ayN!zBoj
TrendMicroTROJ_GEN.R067C0PD323
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.ExplorerHijack.Z82@ayN!zBoj (B)
IkarusTrojan.Win32.Patched
GDataGen:Trojan.ExplorerHijack.Z82@ayN!zBoj
GoogleDetected
AviraTR/Patched.Gen
Antiy-AVLGrayWare/Win32.Patched.bak
XcitiumTrojWare.Win32.Bitrep.IW@7mfe0x
ArcabitTrojan.ExplorerHijack.E52B21
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2473338
ALYacGen:Trojan.ExplorerHijack.Z82@ayN!zBoj
MAXmalware (ai score=99)
VBA32BScope.Trojan.Fuerboos
MalwarebytesGeneric.Trojan.PatchedPE.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R067C0PD323
RisingTrojan.Patch!1.B0CF (CLASSIC)
YandexTrojan.GenAsa!xDVRoGfa5Mk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IW!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Generic.Trojan.PatchedPE.DDS?

Generic.Trojan.PatchedPE.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment