Malware

Heur.Conjar.7 (file analysis)

Malware Removal

The Heur.Conjar.7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Conjar.7 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

sympadwe.be
tumisoney.be
eksyghskgsbakrys.com
msrgejsdyvekadh.com

How to determine Heur.Conjar.7?


File Info:

crc32: CAB86049
md5: 681a0c349f860507831aa1133593560a
name: 681A0C349F860507831AA1133593560A.mlw
sha1: 275d9e1bd6c6b0349cd397197d9ba11859a99435
sha256: 1a121be07e2026d2a46400d831d9de3ea2d1d7bb838f4229783efae569d325d0
sha512: 459319fee61f6f2764a3f98760ebfeedd9d35bbf950936126b4b6120c3463ee4b4feef17a7d9b860b67333a9d7ba11acc5857cbfdbe4b0aff8fd003b959dc29d
ssdeep: 1536:ZjPOaklWIkuvwKxNemVgCpbM9FOz4h6xW3lU+aafbHagkUb+v1WHkX:lsWIkwxXpA9mRxW3lU+lWgUQg
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2009-2011 Foxit Corporation
InternalName: Foxit Reader.exe
FileVersion: 5, 0, 2, 0718
CompanyName: Foxit Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Foxit Reader
SpecialBuild:
ProductVersion: 5, 0, 2, 0718
FileDescription: Foxit Reader 5.0, Best Reader for Everyday Use!
OriginalFilename: Foxit Reader.EXE
Translation: 0x0804 0x04b0

Heur.Conjar.7 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003640b31 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed.22288
ClamAVWin.Trojan.Agent-505832
ALYacGen:Heur.Conjar.7
CylanceUnsafe
ZillyaBackdoor.Buterat.Win32.640
SangforSuspicious.Win32.Save.a
BitDefenderGen:Heur.Conjar.7
K7GWTrojan ( 003640b31 )
Cybereasonmalicious.49f860
CyrenW32/Fareit.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/SpyVoltar.A
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.ULPM.bfpipl
ViRobotBackdoor.Win32.A.Buterat.87552[UPX]
MicroWorld-eScanGen:Heur.Conjar.7
TencentMalware.Win32.Gencirc.10c45dc5
Ad-AwareGen:Heur.Conjar.7
SophosML/PE-A + Mal/Zbot-EZ
ComodoTrojWare.Win32.Remex.bfja@4miupj
BitDefenderThetaGen:NN.ZexaF.34236.fmKfaa1FsKgi
VIPREWorm.Win32.Cridex.ba (v)
McAfee-GW-EditionTrojan-FAAP!681A0C349F86
FireEyeGeneric.mg.681a0c349f860507
EmsisoftGen:Heur.Conjar.7 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Buterat.xx
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.185E9FC
MicrosoftTrojan:Win32/Vundo
SUPERAntiSpywareHeur.Agent/Gen-FakeFoxit
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Conjar.7
AhnLab-V3Trojan/Win32.Jorik.R20057
VBA32BScope.Trojan.Winlock.1215
MAXmalware (ai score=100)
MalwarebytesRansom.FileCryptor
YandexBackdoor.Buterat!qbl2zlSsiq8
IkarusTrojan.Win32.Yakes
FortinetW32/Yakes.B!tr
PandaBck/Qbot.AO

How to remove Heur.Conjar.7?

Heur.Conjar.7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment