Trojan

About “Trojan.Heur.MPacked.Zn0ab09ymvhbj” infection

Malware Removal

The Trojan.Heur.MPacked.Zn0ab09ymvhbj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.MPacked.Zn0ab09ymvhbj virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.MPacked.Zn0ab09ymvhbj?


File Info:

crc32: F28D3C26
md5: c142d9ffba7b7924a1f5568da3b94c37
name: C142D9FFBA7B7924A1F5568DA3B94C37.mlw
sha1: 4c3d6f3da845d86b4cdad9226254f8905f0ca7af
sha256: 38f1b75575f42d3ad8e529408de987033c4138e214059f2274673576d1f1061e
sha512: f7777d6b430419a369da408067745ed7466774b9ac57509813879fbef0d21cc04d72528e4516378d3f9490ead4ad3b2ae8e92024ac1e9e7d3bf4a0854e569be6
ssdeep: 49152:oRRFNImXopKsIpFTQ6FyCo1rz3myH5bpdFsUjsId:oNNjLQAwz3d5bpdXjsI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Trojan.Heur.MPacked.Zn0ab09ymvhbj also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ALYacGen:Trojan.Heur.MPacked.Zn0ab09ymvhbj
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaPacked:Win32/Themida.83c448b1
Cybereasonmalicious.fba7b7
ESET-NOD32a variant of Win32/Packed.Themida.HFK
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderGen:Trojan.Heur.MPacked.Zn0ab09ymvhbj
MicroWorld-eScanGen:Trojan.Heur.MPacked.Zn0ab09ymvhbj
Ad-AwareGen:Trojan.Heur.MPacked.Zn0ab09ymvhbj
SophosMal/EncPk-PC
BitDefenderThetaAI:Packer.5A06B17825
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.c142d9ffba7b7924
EmsisoftGen:Trojan.Heur.MPacked.Zn0ab09ymvhbj (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Multi.fvk
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Gen.bot!i
GDataWin32.Application.PUPStudio.A
McAfeeArtemis!C142D9FFBA7B
MAXmalware (ai score=86)
MalwarebytesPUP.Optional.ChinAd
IkarusTrojan.Win32.Themida
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Application
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Heur.MPacked.Zn0ab09ymvhbj?

Trojan.Heur.MPacked.Zn0ab09ymvhbj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment