Crack Trojan

Trojan.Patched.LH (file analysis)

Malware Removal

The Trojan.Patched.LH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Patched.LH virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Patched.LH?


File Info:

name: 7EF269F1174DAE48D510.mlw
path: /opt/CAPEv2/storage/binaries/14e6aaaaaf7bba164ae53eed793d9c4dbc8f285e3c5ba3b1f7fc74023529dbef
crc32: FEBB1C27
md5: 7ef269f1174dae48d510191abf1f9df8
sha1: 671f072b1d318aa512c26ef0fe1deb826e1bdc5e
sha256: 14e6aaaaaf7bba164ae53eed793d9c4dbc8f285e3c5ba3b1f7fc74023529dbef
sha512: f03bfaefbe79d3845f30f0a06396c22e24d91e09ba8416342f1eb471a00be8c9482919a38ebf7f8bf60ad80d208db6b082d6c1e10f6816b08d95f84bdca1efc5
ssdeep: 6144:oseyuAwDSxiv4J2pZiso6LsByfJm8ZqzJMwqU77d3ngJynUnvB9G:oseyuAwDSxiv4J2posHKyRm8Zq+wqyS2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B534015BFC0B1877E490897697E2AEF10BFE5D6B31D2B87FDBC018411854A89B913872
sha3_384: 79066914caac3d1657f8acbcb657c88d283716acc22a0af6be8b9b2b83aa6bdba3f65d5e70030f581950691c99ccfa01
ep_bytes: 558bec81ec70090000e8b20c00008985
timestamp: 1970-01-01 15:50:05

Version Info:

0: [No Data]

Trojan.Patched.LH also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.CliptoShuffler.tqXq
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Patched.LH
FireEyeGeneric.mg.7ef269f1174dae48
ALYacTrojan.Patched.LH
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Patched.rw
K7AntiVirusVirus ( 0055485e1 )
AlibabaTrojanDownloader:Win32/Lethic.4ac05d01
K7GWVirus ( 0055485e1 )
Cybereasonmalicious.1174da
VirITWin32.Nov15th.A
CyrenW32/ZeroDloader.A.gen!Eldorado
SymantecInfostealer
ESET-NOD32Win32/TrojanDownloader.Agent.EQH
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.WillExec-6356235-0
KasperskyTrojan.Win32.Patched.rw
BitDefenderTrojan.Patched.LH
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastFileRepMalware
TencentVirus.Win32.Patched.kh
Ad-AwareTrojan.Patched.LH
TACHYONWorm/W32.ZeroDownloader
EmsisoftTrojan.Patched.LH (B)
ComodoTrojWare.Win32.Agent.CD@78yzq6
DrWebTrojan.Siggen7.22024
ZillyaTrojan.Patched.Win32.141621
TrendMicroTSPY_ZBOT.SM16
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
SophosMal/Generic-R + Troj/DwnLdr-YLF
IkarusTrojan-Downloader.Win32.Agent
GDataWin32.Trojan.PSE.1229OQH
JiangminTrojanDownloader.Generic.bdga
AviraW32/Infector.Gen
Antiy-AVLTrojan/Generic.ASBOL.C5D0
ArcabitTrojan.Patched.LH
MicrosoftTrojanDownloader:Win32/SmallAgent!atmn
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Androm.R222017
Acronissuspicious
McAfeeArtemis!7EF269F1174D
MAXmalware (ai score=87)
VBA32BScope.TrojanBanker.CliptoShuffler
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTSPY_ZBOT.SM16
RisingBackdoor.Androm!8.113 (TFE:dGZlOgUbZYyTaY7Eug)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.EQH!tr.dldr
BitDefenderThetaAI:Packer.27F4D8301F
AVGFileRepMalware
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Patched.LH?

Trojan.Patched.LH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment