Trojan

Trojan.Heur.Packed.yu1ab4JQOUjb removal tips

Malware Removal

The Trojan.Heur.Packed.yu1ab4JQOUjb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.Packed.yu1ab4JQOUjb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Heur.Packed.yu1ab4JQOUjb?


File Info:

name: F9F134887BBA9B22A6F8.mlw
path: /opt/CAPEv2/storage/binaries/2d540ea4ba3fae6306abf44d581c4ac06c8dd620084ffa0962a8ad814bc4b5df
crc32: CDCE5D65
md5: f9f134887bba9b22a6f864161264b87b
sha1: 09e259422a93993b94d7baf322ac816cc116c2e0
sha256: 2d540ea4ba3fae6306abf44d581c4ac06c8dd620084ffa0962a8ad814bc4b5df
sha512: 3e91a808972bc9c9dfc8f3977040c1ceed2eb5ae253717e91047d19a186c43062734f25a484bb3d2bb660d00da10181d4c5b195b6204959d76f8a1a9cb64c441
ssdeep: 6144:FDN+TGO2ym8305lce/HyF2idZecnl20lHRxp3gN31ueKvaHK9RtL2rmEI45aLRXf:hMX2h8Clce/uF3Z4mxx0O9nLkmuCrzX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C842318A9BE4065CC3652BE8D33B9DB8172EA63091F6A27E0E7CFE31665350F11E50D
sha3_384: c19e9c7ffbcb39577518320779f8b06a7d4aab451cfc21973064ef6fa39d5bb8b17336effb61bd07ca4090d9428284b4
ep_bytes: 6801600301e801000000c3c3553099f5
timestamp: 2004-08-04 06:01:37

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: Wextract
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.2180
Translation: 0x0804 0x04b0

Trojan.Heur.Packed.yu1ab4JQOUjb also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed.Based
MicroWorld-eScanGen:Trojan.Heur.Packed.yu1ab4JQOUjb
FireEyeGeneric.mg.f9f134887bba9b22
ALYacGen:Trojan.Heur.Packed.yu1ab4JQOUjb
MalwarebytesMalware.AI.3214257140
VIPREGen:Trojan.Heur.Packed.yu1ab4JQOUjb
Sangfor[ASPROTECT V2.X REGISTERED -> ALEXEY SOLODOVNIKOV]
K7AntiVirusTrojan ( 005376ae1 )
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.87bba9
BitDefenderThetaAI:Packer.74844E2B23
CyrenW32/Hupigon.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Packed.ASProtect.AAC
TrendMicro-HouseCallMal_Pai-6
Paloaltogeneric.ml
ClamAVWin.Trojan.Dialer-3773
KasperskyPacked.Win32.PePatch.jw
BitDefenderGen:Trojan.Heur.Packed.yu1ab4JQOUjb
NANO-AntivirusTrojan.Win32.Black.cwldnh
AvastWin32:Evo-gen [Susp]
RisingBackdoor.Farfli!1.6495 (CLOUD)
Ad-AwareGen:Trojan.Heur.Packed.yu1ab4JQOUjb
EmsisoftGen:Trojan.Heur.Packed.yu1ab4JQOUjb (B)
ComodoPacked.Win32.Aspack.AB@1s8lrk
ZillyaTrojan.Dialer.Win32.13118
TrendMicroMal_Pai-6
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Behav-160
IkarusPacker.Win32.Klone.ao
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.Packed.yu1ab4JQOUjb
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hupigon3.Gen
Acronissuspicious
McAfeeArtemis!F9F134887BBA
MAXmalware (ai score=89)
VBA32Trojan-Dropper.Kaos
CylanceUnsafe
APEXMalicious
TencentWin32.Trojan.Dialer.Ehhp
YandexTrojan.Dialer!rSNaY4LdhII
MaxSecureTrojan.Malware.2035421.susgen
FortinetW32/Hupigon.GE!tr.bdr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Heur.Packed.yu1ab4JQOUjb?

Trojan.Heur.Packed.yu1ab4JQOUjb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment