Malware

Packer.YodaBased.B (file analysis)

Malware Removal

The Packer.YodaBased.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Packer.YodaBased.B virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

How to determine Packer.YodaBased.B?


File Info:

crc32: 05F8151F
md5: 5a4159ccf32d709acb315c93888bfd3a
name: 5A4159CCF32D709ACB315C93888BFD3A.mlw
sha1: cd2757ae7faffd6e71515c526c13a56e8701928e
sha256: 19a904758c35a94c317a4729f4f5a8eb30e3b6c703385db76079d803929c2363
sha512: a86ae79b0f97476729d8fef61bbc76914ca7c3461865cfe031e019c42e288d64c249262e1c9707f44a8816dcb7117710d44fa939549d70de81eb995ddd4025c4
ssdeep: 12288:Fa+jXP8v4bXZ2rqBv+d5E+afUZfU8yTXIcXSz0E91Gp:Fa+LJ8OF+d5WQfU8ytXSH91G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021
InternalName: AAAA
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Application AAAA
ProductVersion: 1, 0, 0, 1
FileDescription: Application MFC AAAA
OriginalFilename: AAAA.EXE
Translation: 0x040c 0x04b0

Packer.YodaBased.B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Spy.422
MicroWorld-eScanPacker.YodaBased.B
ALYacPacker.YodaBased.B
MalwarebytesMalware.Heuristic.1003
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.cf32d7
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderPacker.YodaBased.B
Ad-AwarePacker.YodaBased.B
SophosGeneric ML PUA (PUA)
ComodoBackdoor.Win32.Hupigon.bolr@1oqk2t
McAfee-GW-EditionBehavesLike.Win32.BadFile.jc
FireEyeGeneric.mg.5a4159ccf32d709a
EmsisoftPacker.YodaBased.B (B)
SentinelOneStatic AI – Malicious PE
GridinsoftTrojan.Heur!.0301A0A1
ArcabitPacker.YodaBased.B
ZoneAlarmPacked.Multi.MultiPacked.gen
GDataPacker.YodaBased.B
McAfeeArtemis!5A4159CCF32D
MAXmalware (ai score=84)
VBA32TScope.Malware-Cryptor.SB
RisingMalware.Heuristic!ET#87% (RDMK:cmRtazpijFNlZBjhvn/xFoiF32Wc)
IkarusPacker.YodaBased.B
eGambitUnsafe.AI_Score_72%
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/QVM18.1.8AC7.Malware.Gen

How to remove Packer.YodaBased.B?

Packer.YodaBased.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment