Trojan

What is “Trojan.Heur.IEC.913efdde329”?

Malware Removal

The Trojan.Heur.IEC.913efdde329 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.IEC.913efdde329 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan.Heur.IEC.913efdde329?


File Info:

name: 5B29886675B8BB5E34FB.mlw
path: /opt/CAPEv2/storage/binaries/dc9e34a2a38b61f3151a4221cd1931a0a78ab39173e331c5c169f9e499517554
crc32: D582AA2A
md5: 5b29886675b8bb5e34fb4525806c2b70
sha1: e5e892dabc9578e05cc21046ce5d22fd5d02dec2
sha256: dc9e34a2a38b61f3151a4221cd1931a0a78ab39173e331c5c169f9e499517554
sha512: 8c1560a1532fafbba85e1e6a0f0c8d770b22044d7b80e505df54da20185c0ed0c1100a674c76d9432bb2a5d6e364fe5ae8189b0236aec166508b04a76765088d
ssdeep: 12288:6mUtfj71OX9gj8ZxKzz/mz3+quH2BE2ylYNDFOgujSgxo:BUtfQX9ImKezUWBAleDKc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEF4E0823790C9B1E0511A35CC1AE6FA862ABFA9CF7095DB37D57F0F35661C19C32229
sha3_384: 96d8de6187910175d2615379c1073888f3678d629752b99be8371a48cfd440156faa3c14bba4a5309a763f2132df6502
ep_bytes: 6a6068f0f34400e8c2200000bf940000
timestamp: 2014-05-05 07:49:11

Version Info:

CompanyName: Element Payment Services
FileDescription: Sandreason
FileVersion: 1.1.854.852
InternalName: Sandreason
LegalCopyright: © 2007, Element Payment Services
LegalTrademarks: Sandreason®
ProductName: Sandreason
ProductVersion: 1.1.854.852
Translation: 0x0409 0x04b0

Trojan.Heur.IEC.913efdde329 also known as:

LionicTrojan.Win32.Zbot.lVvm
CynetMalicious (score: 100)
FireEyeGeneric.mg.5b29886675b8bb5e
McAfeeGenericR-ECO!5B29886675B8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Necurs.uvo
K7AntiVirusSpyware ( 004b8cd91 )
AlibabaTrojanPSW:Win32/Necurs.c20583eb
K7GWSpyware ( 004b8cd91 )
Cybereasonmalicious.675b8b
VirITTrojan.Win32.X-Fiha.BZ
CyrenW32/Trojan.LAEN-7588
SymantecRansom.Cryptolock!g4
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
KasperskyTrojan-Dropper.Win32.Necurs.uvo
BitDefenderGen:Trojan.Heur.IEC.913efdde329
NANO-AntivirusTrojan.Win32.Necurs.cxiwio
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
MicroWorld-eScanGen:Trojan.Heur.IEC.913efdde329
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b16dd4
Ad-AwareGen:Trojan.Heur.IEC.913efdde329
SophosMal/Generic-R + Troj/Zbot-IGM
ComodoMalware@#1hp8kjh1ch720
DrWebTrojan.PWS.Panda.5676
ZillyaDropper.Necurs.Win32.2979
McAfee-GW-EditionGenericR-ECO!5B29886675B8
EmsisoftGen:Trojan.Heur.IEC.913efdde329 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.IEC.913efdde329
JiangminTrojanDropper.Necurs.bjb
WebrootW32.Infostealer.Zeus
AviraTR/Dropper.A.17913
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.9D1E3D
KingsoftWin32.Troj.Necurs.u.(kcloud)
ArcabitTrojan.Heur.IEC.913efdde329
ViRobotTrojan.Win32.Agent.758784.A
ZoneAlarmTrojan-Dropper.Win32.Necurs.uvo
MicrosoftPWS:Win32/Zbot.gen!GO
AhnLab-V3Spyware/Win32.Zbot.R106121
BitDefenderThetaAI:Packer.305052A41F
ALYacGen:Trojan.Heur.IEC.913efdde329
VBA32TrojanDropper.Necurs
RisingTrojan.Spy.Win32.Zbot.hkr (CLOUD)
YandexTrojan.DR.Necurs!nTm1xMJMXrs
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.BXXO!tr
AVGWin32:Malware-gen
PandaGeneric Malware

How to remove Trojan.Heur.IEC.913efdde329?

Trojan.Heur.IEC.913efdde329 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment