Trojan

About “UDS:Trojan.Win32.Inject.apheu” infection

Malware Removal

The UDS:Trojan.Win32.Inject.apheu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Inject.apheu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine UDS:Trojan.Win32.Inject.apheu?


File Info:

name: 3FC3C38DC9969635EB1C.mlw
path: /opt/CAPEv2/storage/binaries/d952fa334ce51fd632e5c3d209c40049edef0d6c1b1f11e617841e6b6c2742ff
crc32: 9B66E87C
md5: 3fc3c38dc9969635eb1ca93ff9bef2b0
sha1: 1a20372de3c4acbe9eeaebb276152fd158ba4500
sha256: d952fa334ce51fd632e5c3d209c40049edef0d6c1b1f11e617841e6b6c2742ff
sha512: a6d87015b9b30e8feae169d2e4c0ec0166522d7c6d61d63783107e3dd06961a63e8285d816d3d02f32a60e5e80bbd663feb7d4138ce034200df4454fb385553a
ssdeep: 98304:WJXYXfhJOV2KCcOk9wFRG+z3h8kEEAZemYBO:2WPFzct9wFvEEAOBO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0F5F141E5C84633D079DCB00866B6FDFB3A0DB139BDA92713A2775B2C303A4B5365A6
sha3_384: 3632533cfcf1a052a429db1a797e3dca4fcdb7b141585b2af14b2421da3ce279da97de2280771025f5f032af2c639e1d
ep_bytes: e81c000000536166656e67696e652053
timestamp: 2012-10-01 16:45:22

Version Info:

0: [No Data]

UDS:Trojan.Win32.Inject.apheu also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.72460988
FireEyeGeneric.mg.3fc3c38dc9969635
SkyhighBehavesLike.Win32.Shohdi.wh
McAfeeArtemis!3FC3C38DC996
Cylanceunsafe
SangforTrojan.Win32.Save.a
AlibabaPacked:Win32/NoobyProtect.4e2a66ca
K7GWTrojan ( 00379e621 )
K7AntiVirusTrojan ( 00379e621 )
BitDefenderThetaGen:NN.ZexaF.36802.ltW@a8p!4Nob
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.NoobyProtect.E suspicious
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H07K823
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyUDS:Trojan.Win32.Inject.apheu
BitDefenderTrojan.GenericKD.72460988
EmsisoftTrojan.GenericKD.72460988 (B)
VIPRETrojan.GenericKD.72460988
Trapminemalicious.high.ml.score
SophosMal/Generic-S
MAXmalware (ai score=82)
GoogleDetected
VaristW32/S-e743b39f!Eldorado
Antiy-AVLGrayWare/Win32.SafeGuard.a
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumTrojWare.Win32.Amtar.KNB@4wlm66
ArcabitTrojan.Generic.D451AABC
ZoneAlarmUDS:Trojan.Win32.Inject.apheu
GDataWin32.Trojan.PSE.5RRKNR
CynetMalicious (score: 100)
VBA32BScope.Trojan.CryptInject
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Packed.NoobyProtect.E

How to remove UDS:Trojan.Win32.Inject.apheu?

UDS:Trojan.Win32.Inject.apheu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment