Trojan

Trojan.Packed.53389 (file analysis)

Malware Removal

The Trojan.Packed.53389 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Packed.53389 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Packed.53389?


File Info:

name: FA7C2F63D14E13B8F593.mlw
path: /opt/CAPEv2/storage/binaries/8f61ed6384a427ce559ee0d794930a9197d412e3e6b6e7aa297404ac44f4b8f0
crc32: 4017C00A
md5: fa7c2f63d14e13b8f59394098664827c
sha1: 9fd24f3f730ae0cf77d3223a4dcf8a6e37102eef
sha256: 8f61ed6384a427ce559ee0d794930a9197d412e3e6b6e7aa297404ac44f4b8f0
sha512: 5895e7524a25d4f1bd90f8572c5a07b634cb5cd35184dd1c132862f77597e0da8b838a7f4d49f9751903c93f1361fa36b87e9e4ef6689ba94dc94a7b9e432467
ssdeep: 24576:YYjsgAbd34m5nW7aZZErEWPNDOOAdVXLQFBysXl1frlvg1fLZ:e7bdo2n3ZGwWPNDOOaeFBzfrlvgNF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183452361BF29C4FBECA050334E2BDA1247213DBC5F26150B629FB71A69733622D1E562
sha3_384: d60cee12b6f50dd2ee60f0d9f2c99ade1d82645d6b2d31397128820ba723d8a0785e2ef190c80f34f0db574728635c74
ep_bytes: 60be009043008dbe0080fcff5783cdff
timestamp: 2004-12-26 15:34:24

Version Info:

0: [No Data]

Trojan.Packed.53389 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.Packed.53389
McAfeeArtemis!FA7C2F63D14E
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7AntiVirusTrojan ( 003b1b581 )
AlibabaTrojanPSW:Win32/LdPinch.fb13e977
K7GWTrojan ( 003b1b581 )
Cybereasonmalicious.3d14e1
CyrenW32/SuspPack.DH.gen!Eldorado
SymantecTrojan.ADH
ESET-NOD32a variant of Generik.DHJGCLX
APEXMalicious
ClamAVWin.Downloader.94039-1
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Packed.53389
NANO-AntivirusTrojan.Win32.Renaz.czzyyt
AvastWin32:Malware-gen
RisingTrojan.Win32.Generic.126D659B (C64:YzY0Opnt1QNK0qcX)
EmsisoftTrojan.Packed.53389 (B)
ComodoMalware@#3o0ksn0mhn3f
TrendMicroCryp_Xed-12
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
FireEyeTrojan.Packed.53389
SophosMal/Packer
IkarusTrojan-PWS.Win32.LdPinch
JiangminTrojan/PSW.OnLineGames.bwdz
WebrootW32.Malware.Heur
Antiy-AVLTrojan/Generic.ASMalwS.29925BD
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.Packed.53389
ALYacTrojan.Packed.53389
MAXmalware (ai score=84)
VBA32Trojan.Tiggre
TrendMicro-HouseCallCryp_Xed-12
YandexTrojan.Renaz!xv76NyF0VoE
SentinelOneStatic AI – Malicious SFX
BitDefenderThetaGen:NN.ZexaE.34182.aiGeaGPp0Bfi
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Packed.53389?

Trojan.Packed.53389 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment