Malware

Heur.Codenox.2 removal

Malware Removal

The Heur.Codenox.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Codenox.2 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Heur.Codenox.2?


File Info:

name: E799202A567C2C2B4316.mlw
path: /opt/CAPEv2/storage/binaries/38c4523d976385709367e3dfc653508b5c5bdfaa4ed8aebc3f136953bad1b5b6
crc32: 092AB71C
md5: e799202a567c2c2b43166e6ac56f1501
sha1: 016dfc02c510e402a158b847a98d2e916bc108d0
sha256: 38c4523d976385709367e3dfc653508b5c5bdfaa4ed8aebc3f136953bad1b5b6
sha512: 9e6ad787940ccf528bea589e249f94f997c29f12dadd12906e1681f7b5f7944b3ff12cd42981233c5bd94a483f970ab6fab1bf0b638a3acf710d184b7b7db56a
ssdeep: 24576:gQf+ta5/AXOGO0IQi/oIvI3FSA8+sIYsb:1fBhAX1IQUhA1SIjb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1240523674519116AD0F27AF209C5DECB029B691C374840AF290991DBFF63AEB327D39C
sha3_384: 840fdf2a1fb12218238239f4774bc12c56ca5a543413c130fc466634983577cd74bccd03e3c86f41182d02c3562faf86
ep_bytes: 558bec83e4f881ece40c0000535657e8
timestamp: 1970-01-01 00:00:01

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Install.exe
LegalCopyright:
OriginalFilename: Install.exe
ProductName:
ProductVersion: 1.0.0.0
Packager: Xenocode Virtual Application Studio 2009
PackagerVersion: 7.0.162

Heur.Codenox.2 also known as:

LionicTrojan.Win32.Ardamax.l!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.15547
MicroWorld-eScanGen:Heur.Codenox.2
FireEyeGeneric.mg.e799202a567c2c2b
ALYacGen:Heur.Codenox.2
SangforSpyware.Win32.Ardamax.vl
AlibabaTrojanSpy:Win32/Ardamax.1ca8911a
Cybereasonmalicious.a567c2
BitDefenderThetaGen:NN.ZexaF.34182.Yy3@amKFW6n
CyrenW32/Injector.FA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/KeyLogger.Ardamax
Paloaltogeneric.ml
ClamAVWin.Trojan.Poison-637
KasperskyTrojan-Spy.Win32.Ardamax.vl
BitDefenderGen:Heur.Codenox.2
NANO-AntivirusTrojan.Win32.Bifrose.hansw
AvastWin32:Malware-gen
TencentWin32.Trojan.Ardamax.Alin
EmsisoftGen:Heur.Codenox.2 (B)
ComodoBackdoor.Win32.Poison.~AB@ttkg8
VIPRETrojan.Win32.Generic!BT
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Buzus
JiangminBackdoor/Poison.ceq
ViRobotBackdoor.Win32.Bifrose.361333
GDataGen:Heur.Codenox.2
CynetMalicious (score: 100)
McAfeeBackDoor-DKI.gen.ak
MAXmalware (ai score=87)
VBA32BackDoor.Poison
APEXMalicious
RisingSpyware.Ardamax!8.F6 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetBDoor.DKI!tr.bdr
WebrootW32.Bifrose.Gen
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Heur.Codenox.2?

Heur.Codenox.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment