Malware

Heur.IPZ.4 (file analysis)

Malware Removal

The Heur.IPZ.4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.IPZ.4 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Heur.IPZ.4?


File Info:

name: 076919686244DE0455B3.mlw
path: /opt/CAPEv2/storage/binaries/3e13aa868c0b9def591227c134949c19ca41eaf73cad316d34676c5617b416cc
crc32: EFFC5C4A
md5: 076919686244de0455b3b14f67d29d03
sha1: 15a935870d367c8716cf38b643304c8fd4766d73
sha256: 3e13aa868c0b9def591227c134949c19ca41eaf73cad316d34676c5617b416cc
sha512: 37db2ea5e1fd407e739dd3e6e57f2509bace4c8631e6df73f39eb07c72c9c5d95c3cb7bb2f5ff4fbd34b155efb60369fe3351595cc8ba0f96b691696672161d2
ssdeep: 3072:5V3poTmPfYN4omljC1HyJ2oifphYSoA0GbhbhijqiUDC/m:emfnomlkLDY5A0Gbvijq/DD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135D3E1422034F6B2C90D437852CEFA571FACFCD59700AA8954A564EB1BCFCA4587B3A7
sha3_384: 6770989b82862238f803167d076fa5bfef25fc4e5a854246c209b93488dc2584db79450ffa260ce70ba8b1578ccae344
ep_bytes: 833da0a54100007535e96c144000ff25
timestamp: 1992-06-19 22:22:17

Version Info:

FileDescription: Downloader
FileVersion: 1, 0, 0, 0
InternalName: Downloader
LegalCopyright: Copyright 2013
OriginalFilename: Downloader.exe
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
Translation: 0x0419 0x04e3

Heur.IPZ.4 also known as:

BkavW32.FamVT.LoadMoneyB.Trojan
LionicTrojan.Win32.CodecPack.lvPr
Elasticmalicious (high confidence)
DrWebTrojan.LoadMoney.225
MicroWorld-eScanGen:Heur.IPZ.4
FireEyeGeneric.mg.076919686244de04
CAT-QuickHealTrojan.Sisproc.A6
McAfeeDownloader-FWY!076919686244
MalwarebytesGeneric.Malware.AI.DDS
ZillyaAdware.AgentCRT.Win32.942
SangforPUA.Win32.Sign.a
K7AntiVirusTrojan ( 0040f6ca1 )
K7GWTrojan ( 0040f6ca1 )
CrowdStrikewin/grayware_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36196.iy1@aKrcaMhc
VirITTrojan.Win32.Downloader.B
CyrenW32/LoadMoney.L.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/LoadMoney.AO potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Agent-1369627
Kasperskynot-a-virus:Downloader.Win32.LMN.gen
BitDefenderGen:Heur.IPZ.4
NANO-AntivirusTrojan.Win32.LMN.csspdk
SUPERAntiSpywareAdware.LoadMoney/Variant
AvastWin32:Trojan-gen
TencentTrojan.Win32.Downloader.abp
EmsisoftApplication.InstallMon (A)
F-SecureProgram.APPL/Downloader.ghk
BaiduWin32.Trojan.Kryptik.ae
VIPREGen:Heur.IPZ.4
TrendMicroPossible_Ogimant
McAfee-GW-EditionDownloader-FWY!076919686244
Trapminemalicious.high.ml.score
SophosTroj/LdMon-D
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.IPZ.4
JiangminDownloader.LMN.jnk
GoogleDetected
AviraAPPL/Downloader.ghk
MAXmalware (ai score=89)
Antiy-AVLRiskWare[Downloader]/Win32.LMN
XcitiumTrojWare.Win32.Kryptik.BEUX@52xauq
ArcabitTrojan.IPZ.4
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.gen
MicrosoftPUAAdvertising:Win32/LoadMoney
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.LoadMoney.C216508
VBA32Malware-Cryptor.Limpopo
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallPossible_Ogimant
RisingAdware.LoadMoney!1.AE7B (CLASSIC)
YandexTrojan.Agent!N1vf/eP9cYE
IkarusVirus.Win32.Cryptor
MaxSecurenot-a-virus:Downloader.LMN.gen
FortinetRiskware/LMN
AVGWin32:Trojan-gen
Cybereasonmalicious.86244d
DeepInstinctMALICIOUS

How to remove Heur.IPZ.4?

Heur.IPZ.4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment