Malware

About “Heur.Conjar.5” infection

Malware Removal

The Heur.Conjar.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Conjar.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:51333
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Heur.Conjar.5?


File Info:

name: 39A6FFF2B302A3BAA8B4.mlw
path: /opt/CAPEv2/storage/binaries/b3637fff403d41bfbbe92fe0036076de9452a9c7fe133f7922a07287c4eeff66
crc32: 508F0295
md5: 39a6fff2b302a3baa8b48fd5b603221f
sha1: 0168c3e6ad8acb29dc32e984bc6a8efc5494ecdf
sha256: b3637fff403d41bfbbe92fe0036076de9452a9c7fe133f7922a07287c4eeff66
sha512: 6f47fbaa6605d61d9ac7517d1e80984d5b641ec7419e54aef8435c4e1f0e63641049bc2818edeb83f7ec93f58a5c02f9b6723089f4b5b2dd6a4c0d6a66400e45
ssdeep: 3072:Xf1YvXMIG1fOR/QUqhIQzMbxq3QB36MZudFmeOaWPvPqh8VpECaLNiwGMUjDXkTL:P1wW1GR/tqsNoO6FmeOaWHPXgNiDQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18114E054DA77A9D8E7FD17B86CD7A05CB28920D3B951681C2B75C2FAB0913A0B2332C5
sha3_384: fed60b44cd94f58c882cbfcc3e8f1f707aa8614e4b026c8ade31a717fc633f58a9cdd1c6bdcba7d8d1645bf4f2862e60
ep_bytes: 558bff8bec81ec64040000c70424ffff
timestamp: 2005-10-25 03:04:56

Version Info:

0: [No Data]

Heur.Conjar.5 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lred
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Conjar.5
CylanceUnsafe
ZillyaBackdoor.Gbot.Win32.3587
SangforTrojan.Win32.Conjar.5
K7AntiVirusBackdoor ( 003210941 )
BitDefenderGen:Heur.Conjar.5
K7GWBackdoor ( 003210941 )
Cybereasonmalicious.2b302a
BitDefenderThetaGen:NN.ZexaF.34182.lqW@aKnAYNci
VirITTrojan.Win32.Cryptor.B
CyrenW32/Goolbot.K.gen!Eldorado
SymantecBackdoor.Cycbot!gen8
ESET-NOD32a variant of Win32/Kryptik.TZC
TrendMicro-HouseCallBKDR_CYCBOT.SME3
Paloaltogeneric.ml
ClamAVWin.Trojan.Gbot-18
KasperskyBackdoor.Win32.Gbot.por
AlibabaBackdoor:Win32/Obfuscator.16e3698a
NANO-AntivirusTrojan.Win32.Gbot.ejmll
ViRobotBackdoor.Win32.A.Gbot.192000.BC
TencentWin32.Backdoor.Gbot.vvq
EmsisoftGen:Heur.Conjar.5 (B)
ComodoTrojWare.Win32.Kryptik.TTW@4hhnux
DrWebBackDoor.Gbot.235
VIPRETrojan.Win32.FakeAV.IS (v)
TrendMicroBKDR_CYCBOT.SME3
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Mal/FakeAV-IS
APEXMalicious
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen8
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Gbot
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GDataWin32.Trojan.Repno.A@gen
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R13582
McAfeeBackDoor-EXI.gen.u
TACHYONBackdoor/W32.GBot.192000.AM
VBA32BScope.Trojan.Cycbot.1212
MalwarebytesBackdoor.Bot
PandaTrj/Cycbot.gen
RisingTrojan.Lvvm!1.990B (CLASSIC)
YandexBackdoor.Gbot!FIabGanh9zs
IkarusBackdoor.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gbot.QAU!tr
AVGWin32:Cybota [Trj]
AvastWin32:Cybota [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Heur.Conjar.5?

Heur.Conjar.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment