Trojan

Trojan.Heur.ii0arrDdgYaiu removal instruction

Malware Removal

The Trojan.Heur.ii0arrDdgYaiu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.ii0arrDdgYaiu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (14 unique times)
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.youtube.com
www.bing.com
ocsp.pki.goog
i.ytimg.com
fonts.googleapis.com
fonts.gstatic.com
r1—sn-4g5e6ney.googlevideo.com
ssl.gstatic.com

How to determine Trojan.Heur.ii0arrDdgYaiu?


File Info:

crc32: 8EEEDBDD
md5: b685aea89b31c61711dc47cbd6f682de
name: B685AEA89B31C61711DC47CBD6F682DE.mlw
sha1: 658942df26a969d06b8e7bba362c0824a782b28d
sha256: dcba7e9c5492268b97f5b93befe0d955206b8ae9db47660746a67920b901d426
sha512: 923cc929f8725c82a502b56867aafe469dfd72c0b16e7b442eaac6940494d21b6bae86967ab7146c79630cbc7c884fc42dccad8fd7d6059591a458f1d9a24211
ssdeep: 3072:psa90U40cTxMOvMOb8YnR0Qav5KLcC7W/r/23M7b/hYtQ5pv7:m/MOvMOgQlaxKLciq+3M7b/hYeXv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: project1
FileVersion: 1.00
CompanyName: Particular
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: project1.exe

Trojan.Heur.ii0arrDdgYaiu also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.ii0arrDdgYaiu
ALYacGen:Trojan.Heur.ii0arrDdgYaiu
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusTrojan ( 00171bc41 )
BitDefenderGen:Trojan.Heur.ii0arrDdgYaiu
K7GWTrojan ( 00171bc41 )
Cybereasonmalicious.89b31c
CyrenW32/SuspPack.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Ructo.I!genus
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyTrojan.Win32.Vilsel.afya
AlibabaWorm:Win32/Vilsel.d40c839c
NANO-AntivirusTrojan.Win32.CFI.jiduh
ViRobotTrojan.Win32.A.Vilsel.139776.AG
AegisLabTrojan.Win32.Vilsel.4!c
TencentWin32.Trojan.Vilsel.Pfsv
Ad-AwareGen:Trojan.Heur.ii0arrDdgYaiu
SophosML/PE-A + Mal/Particula-A
ComodoTrojWare.Win32.PSW.Ldpinch.~NNT@1op6ij
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebBackDoor.Generic.3105
ZillyaTrojan.Vilsel.Win32.24624
TrendMicroWORM_RUCTO.SMI
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cc
FireEyeGeneric.mg.b685aea89b31c617
EmsisoftGen:Trojan.Heur.ii0arrDdgYaiu (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vilsel.zmg
Webrootnone
AviraTR/Crypt.CFI.Gen
eGambitGeneric.Malware
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Vilsel
KingsoftWin32.Hack.MorphineT.a.(kcloud)
MicrosoftTrojan:Win32/Ditertag.A
ArcabitTrojan.Heur.ii0arrDdgYaiu
SUPERAntiSpywareWorm.Ructo/Variant
ZoneAlarmTrojan.Win32.Vilsel.afya
GDataGen:Trojan.Heur.ii0arrDdgYaiu
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSNPass.R1900
Acronissuspicious
McAfeeGeneric BackDoor.wg
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.Heuristic.1006
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/VB.NTU
TrendMicro-HouseCallWORM_RUCTO.SMI
YandexTrojan.Vilsel.Gen!Pac.3
IkarusTrojan-Downloader.Win32.VB
MaxSecureTrojan.Vilsel.agwm
FortinetW32/Vilsel.GA!tr
BitDefenderThetaAI:Packer.CD616BF61D
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.c17

How to remove Trojan.Heur.ii0arrDdgYaiu?

Trojan.Heur.ii0arrDdgYaiu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment