Malware

Heur.Honret.2 (B) information

Malware Removal

The Heur.Honret.2 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Honret.2 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Heur.Honret.2 (B)?


File Info:

crc32: 26A9DD03
md5: f2f6a0f59a5783c865ba63eb5d38f6d0
name: upload_file
sha1: a36642fddee370ce2c106eadc8ba85471c3864cb
sha256: 2ae6e37e0cbca0a3198ad915d1b4bd801453370b3af1223b144b9125d5ad550c
sha512: a5ac5668f8cf3f99a2340d89a6c6d2985eeefea6ebbd960340e7091de95784d60bc9f0dd6a46df95c5de82ddc16504b5f142fe8d6c5bee58010af1bf41b2142f
ssdeep: 12288:TB8tzikyUxNxUNxNxAixNxgxNxgb/E0ZOh1ETvQc:o7yXb/E6OzETT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Heur.Honret.2 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.50902
MicroWorld-eScanGen:Heur.Honret.2
FireEyeGeneric.mg.f2f6a0f59a5783c8
McAfeeGenericRXAA-AA!F2F6A0F59A57
SangforMalware
BitDefenderGen:Heur.Honret.2
Cybereasonmalicious.59a578
TrendMicroBackdoor.Win32.QAKBOT.SMF
BitDefenderThetaGen:NN.ZexaF.34152.xtW@aeYtMZm
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
RisingMalware.Undefined!8.C (TFE:dGZlOgE0gVCbfSKJOQ)
Ad-AwareGen:Heur.Honret.2
SophosMal/EncPk-APV
F-SecureTrojan.TR/Crypt.EPACK.Gen2
Invinceaheuristic
FortinetW32/Cridex.VHO!tr
EmsisoftGen:Heur.Honret.2 (B)
eGambitUnsafe.AI_Score_78%
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Honret.2
MicrosoftTrojan:Win32/Qakbot.AR!MTB
CynetMalicious (score: 100)
VBA32BScope.Trojan.Encoder
ALYacGen:Heur.Honret.2
CylanceUnsafe
ESET-NOD32a variant of Win32/Kryptik.HFNH
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SMF
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
GDataGen:Heur.Honret.2
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Generic/Trojan.033

How to remove Heur.Honret.2 (B)?

Heur.Honret.2 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment