Malware

Heur.Conjar.12 (B) removal instruction

Malware Removal

The Heur.Conjar.12 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Conjar.12 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Heur.Conjar.12 (B)?


File Info:

name: 2C57FE1384CCE7DB36C8.mlw
path: /opt/CAPEv2/storage/binaries/46cb5c9b33d395d1cef54367f7c64c72496c796c417492bd62563bd52395abf0
crc32: F878AEB9
md5: 2c57fe1384cce7db36c868c9df3ab747
sha1: 9d929c4bf96534cb94b46542265d23aa43bf229e
sha256: 46cb5c9b33d395d1cef54367f7c64c72496c796c417492bd62563bd52395abf0
sha512: d0d71cda52a1cd64c166f30c2ea2a51280ae91fba3289c268762169a7ca5ce845cf8566d56c7deadcb5472bc666b2880104bbcfdb792d9f1b091403b4f48dc20
ssdeep: 6144:ctjp0OqvoArlO+BeiK2/pWTxq/fnx7GDrRcJIcxyCq0hzfq:Ekvo8sVq/PERcHxywq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC44F1431B94AC17C997D77C6206DAFCA0AB9BC09A562353B8D06A0ED7DC1D4BD3C21B
sha3_384: ef08ebfbbda49e0a0e6b6065be938a94c57620e2049fbb4b53403a2428464d0f0d2a1e8edd4a80b31ba0a8af63c4cb58
ep_bytes: 558bec83ec70892dd812400060c745c4
timestamp: 2012-04-29 20:20:29

Version Info:

0: [No Data]

Heur.Conjar.12 (B) also known as:

LionicTrojan.Win32.Generic.lw2L
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Conjar.12
FireEyeGeneric.mg.2c57fe1384cce7db
CAT-QuickHealTrojanPWS.Zbot.Y
CylanceUnsafe
VIPRETrojan.Win32.Zbot.fg (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f02a1 )
AlibabaTrojanPSW:Win32/Reveton.5656e46c
K7GWTrojan ( 0040f02a1 )
Cybereasonmalicious.384cce
BaiduWin32.Adware.Kryptik.b
VirITTrojan.Win32.Foreign.ONZ
CyrenW32/Zbot.DQ.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Zbot.AAN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-1331
KasperskyPacked.Win32.Krap.iu
BitDefenderGen:Heur.Conjar.12
NANO-AntivirusTrojan.Win32.Zbot.ornxf
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Karagany
TencentTrojan.Win32.spy.tqw
Ad-AwareGen:Heur.Conjar.12
EmsisoftGen:Heur.Conjar.12 (B)
ComodoTrojWare.Win32.Kryptik.ASR@4oc4x0
DrWebTrojan.PWS.Panda.2122
ZillyaTrojan.Zbot.Win32.59638
TrendMicroTROJ_AGENT_007956.TOMB
McAfee-GW-EditionPWS-Zbot.gen.bex
SophosML/PE-A + Troj/Zbot-DHN
IkarusTrojan-PWS.Win32.Zbot
JiangminTrojanSpy.Zbot.bqvf
WebrootW32.Suspicious.Heur
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.43B9
KingsoftHeur.SSC.2764147.0010.(kcloud)
MicrosoftPWS:Win32/Zbot.gen!AF
ViRobotTrojan.Win32.A.Zbot.276576.B
GDataGen:Heur.Conjar.12
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R24106
Acronissuspicious
McAfeePWS-Zbot.gen.bex
TACHYONTrojan-Spy/W32.ZBot.276576.B
VBA32BScope.Trojan.Zbot.2842
MalwarebytesMalware.AI.815042862
TrendMicro-HouseCallTROJ_AGENT_007956.TOMB
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!KaagRtaUf4M
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3902669.susgen
FortinetW32/Lockscreen.LOA!tr
BitDefenderThetaGen:NN.ZexaF.34212.qqX@aurxpTf
AVGWin32:Karagany
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Heur.Conjar.12 (B)?

Heur.Conjar.12 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment