Crack Trojan

About “Trojan.Patched.dj” infection

Malware Removal

The Trojan.Patched.dj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Patched.dj virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for fileless persistence
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior

How to determine Trojan.Patched.dj?


File Info:

name: 0409DD367A260C690D13.mlw
path: /opt/CAPEv2/storage/binaries/b8eeeb1a778e90970174e7b9faca190e4dc6bea2e37971eb63acd64bc25a28a1
crc32: 635DC8C6
md5: 0409dd367a260c690d13f7860e4a7cd9
sha1: 00ad539c31150be765985b656c4ef8ddbafc9b96
sha256: b8eeeb1a778e90970174e7b9faca190e4dc6bea2e37971eb63acd64bc25a28a1
sha512: 0f87dfe6a72a4f2871403b3e98df6d90e10b581b9b7109388ee0ac4ece624b202df62935f7cbfa3ba743adc8d4ccc88e57209fd4aea989d6b12bd99527e7b6ad
ssdeep: 12288:XToPWBv/cpGrU3y31jPjQN8G/rDrgAx+PpzdzHX:XTbBv5rUCjLQNTMA0Pppz3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7C4D002BAD694B2D16219715A75AB105A3F79201F7ACADBB3CC0A5DDB734C0DB307B2
sha3_384: 6d2e46d2b761ed1c0ea181d71d3a174676eb3906463a721b2f2dbd39122462aee5750cdc58383644cc341e3078ef9c68
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Trojan.Patched.dj also known as:

BkavW32.AIDetect.malware2
ClamAVWin.Dropper.Wapomi-9375927-0
SangforSuspicious.Win32.Save.a
BitDefenderWin32.SlugIn.A
Cybereasonmalicious.67a260
ArcabitWin32.SlugIn.A
VirITWin32.Slugin.A
CyrenW32/Slugin.B
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Slugin.a
NANO-AntivirusVirus.Win32.Slugin.ddowbn
MicroWorld-eScanWin32.SlugIn.A
RisingTrojan.Runner/VBS!1.A439 (CLASSIC)
EmsisoftWin32.SlugIn.A (B)
DrWebWin32.Wplugin.2
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.0409dd367a260c69
SophosGeneric ML PUA (PUA)
AviraHEUR/AGEN.1242193
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Sabsik.EN.B!ml
AhnLab-V3Malware/Win.Generic.C5033732
Acronissuspicious
VBA32Trojan.Patched.dj
MalwarebytesNimnul.Virus.FileInfector.DDS
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34712.HyZ@a43ZTIgO
AVGWin32:Patched-HO [Trj]
AvastWin32:Patched-HO [Trj]

How to remove Trojan.Patched.dj?

Trojan.Patched.dj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment