Malware

Heur.Japik.2 (B) removal instruction

Malware Removal

The Heur.Japik.2 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Japik.2 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Heur.Japik.2 (B)?


File Info:

name: D21CFBF0DCC2152DA4D4.mlw
path: /opt/CAPEv2/storage/binaries/d3b4204ff0e2ba4142c6782019f2a4e9437875c607aac2280e908a683dbbde2a
crc32: 464BF50C
md5: d21cfbf0dcc2152da4d4b5702fcca528
sha1: e383b09455c9ce478125730d36e30c3e281f3819
sha256: d3b4204ff0e2ba4142c6782019f2a4e9437875c607aac2280e908a683dbbde2a
sha512: c80280de302f645575913239c59da2c2da1544c13ba7b96fe08f68f33345802cab897f0a871737ebe804e9ffa38d6f0fbcb9380bbc428e34b5419dbfb0d5e3ae
ssdeep: 6144:Q5CFwkVdy8ly0ZYv51234BBWDoP1e6AhCJsaE+N8PVT5BcOsw:o+wcdyjEYv512IADoP1uJ4YBBB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B894E035F631513FCC8E5771613293098E642808BA69316BA68D0CFF7A79F897B06D6C
sha3_384: c718a9a9fc4c3039a69cbaf9fa72045fcfe00bd6267c0011e48086b78d119aadf69693797357459ce03299aa369c4b6d
ep_bytes: 558bec83ec68535657c745d850164000
timestamp: 2012-10-28 19:40:20

Version Info:

0: [No Data]

Heur.Japik.2 (B) also known as:

LionicTrojan.Win32.Zbot.lDMg
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Japik.2
FireEyeGeneric.mg.d21cfbf0dcc2152d
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeePWS-Zbot.gen.bgk
CylanceUnsafe
VIPRETrojan.Win32.Reveto.Ac (v)
SangforTrojan.Win32.Zbot.GO
K7AntiVirusTrojan ( 0040f1aa1 )
AlibabaTrojanPSW:Win32/Bublik.09955d0d
K7GWTrojan ( 0040f1aa1 )
Cybereasonmalicious.0dcc21
BaiduWin32.Trojan.Kryptik.et
VirITTrojan.Win32.Generic.AEUD
CyrenW32/Zbot.FL.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32Win32/Spy.Zbot.AAN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zbot-9773638-0
KasperskyTrojan.Win32.Bublik.oui
BitDefenderGen:Heur.Japik.2
NANO-AntivirusTrojan.Win32.Panda.bbwedu
SUPERAntiSpywareTrojan.Agent/Gen-Bublik
AvastWin32:DangerousSig [Trj]
TencentMalware.Win32.Gencirc.10b3eb76
Ad-AwareGen:Heur.Japik.2
TACHYONTrojan/W32.Bublik.424208
SophosML/PE-A + Troj/Zbot-DHN
ComodoTrojWare.Win32.Kryptik.SES@4s5v9d
DrWebTrojan.Packed.23728
ZillyaTrojan.Bublik.Win32.2728
TrendMicroTSPY_ZBOT.SM14
McAfee-GW-EditionPWS-Zbot.gen.bgk
EmsisoftGen:Heur.Japik.2 (B)
IkarusTrojan.Win32.Bublik
JiangminTrojanSpy.Zbot.cike
eGambitPE.Heur.InvalidSig
AviraTR/PSW.Tepfer.B
Antiy-AVLTrojan/Win32.Bublik
MicrosoftPWS:Win32/Zbot!GO
ViRobotTrojan.Win32.A.Zbot.424208
ZoneAlarmTrojan.Win32.Bublik.oui
GDataGen:Heur.Japik.2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bublik.R41429
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.zmX@aCguLjb
ALYacGen:Heur.Japik.2
MAXmalware (ai score=99)
VBA32BScope.Malware-Cryptor.SB.01798
MalwarebytesMalware.AI.948992402
TrendMicro-HouseCallTSPY_ZBOT.SM14
RisingSpyware.Zbot!8.16B (TFE:dGZlOgLMxfspXBjBsA)
YandexTrojan.Bublik!8RinEucYVs8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Packed.Krap.iu
FortinetW32/Lockscreen.LOA!tr
WebrootW32.Infostealer.Zeus
AVGWin32:DangerousSig [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Heur.Japik.2 (B)?

Heur.Japik.2 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment