Malware

What is “Heur.RI.1 (B)”?

Malware Removal

The Heur.RI.1 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.RI.1 (B) virus can do?

  • At least one process apparently crashed during execution
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Uses suspicious command line tools or Windows utilities

Related domains:

sky.hobuff.info

How to determine Heur.RI.1 (B)?


File Info:

crc32: 6AEA28F0
md5: e0f3305c23847ddc275f8cc8fb203c4d
name: 86.exe
sha1: 0e64f6e27531cad4d85d13cecfe77af41b4bae71
sha256: 0589a7769e5267fff3f60688d3197b585be1bb4a82cf39a4b8a35c1225ad7fd3
sha512: 43cba023167c13a22e9bc911edfed699115150206333b6ea78cff0c67da604a0f816f15faba89a170ed25247829e8868543c6daf798d2b1ef62fce30193518a0
ssdeep: 768:cw/iOWTK3JWhOM/qZh7UJGcZ/aQAF+nbcuyD7U7s9:DQK52fqZSIArQ+nouy87s9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: MFC KING 2017
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Application MFC KING 2017
ProductVersion: 1, 0, 0, 1
FileDescription: Application MFC MFC KING 2017
OriginalFilename: MFC KING 2017.EXE
Translation: 0x040c 0x04b0

Heur.RI.1 (B) also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.DownLoader23.39271
MicroWorld-eScanGen:Heur.RI.1
CAT-QuickHealTrojan.SiscosRI.S8512495
Qihoo-360Win32/Trojan.ab1
McAfeeArtemis!E0F3305C2384
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Siscos.4!c
SangforMalware
K7AntiVirusTrojan ( 00522d7f1 )
BitDefenderGen:Heur.RI.1
K7GWTrojan ( 00522d7f1 )
Cybereasonmalicious.c23847
BitDefenderThetaGen:NN.ZexaF.34104.cmKfaiKZIIde
F-ProtW32/Siscos.E.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Siscos-6993581-0
GDataGen:Heur.RI.1
KasperskyTrojan.Win32.Siscos.wbm
AlibabaBackdoor:Win32/Siscos.c0779bee
NANO-AntivirusTrojan.Win32.Siscos.enrcbv
TencentMalware.Win32.Gencirc.10b3bfff
Ad-AwareGen:Heur.RI.1
SophosTroj/AutoG-AD
ComodoTrojWare.Win32.GameThief.Magania.~NWABU@18g2sq
F-SecureHeuristic.HEUR/AGEN.1003906
ZillyaTrojan.Siscos.Win32.5474
Invinceaheuristic
McAfee-GW-EditionGenericRXIX-IO!247FD829B7DB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.e0f3305c23847ddc
EmsisoftGen:Heur.RI.1 (B)
IkarusTrojan.Win32.Farfli
CyrenW32/Siscos.E.gen!Eldorado
JiangminTrojan.Siscos.ks
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1003906
Antiy-AVLTrojan/Win32.Siscos
Endgamemalicious (moderate confidence)
ArcabitTrojan.RI.1
SUPERAntiSpywareBackdoor.Farfli/Variant
ZoneAlarmTrojan.Win32.Siscos.wbm
MicrosoftBackdoor:Win32/Venik.F
AhnLab-V3Trojan/Win32.RL_Siscos.R302641
VBA32Trojan.Siscos
ALYacGen:Heur.RI.1
MAXmalware (ai score=100)
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
ZonerTrojan.Win32.70935
ESET-NOD32Win32/Farfli.CEN
RisingBackdoor.Venik!8.11E (CLOUD)
YandexTrojan.Siscos!SVEFMyd2cvk
SentinelOneDFI – Suspicious PE
eGambitTrojan.Generic
FortinetW32/Siscos.WBM!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.10800876.susgen

How to remove Heur.RI.1 (B)?

Heur.RI.1 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment