Malware

Heur.SEPhish.2 removal instruction

Malware Removal

The Heur.SEPhish.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.SEPhish.2 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Heur.SEPhish.2?


File Info:

crc32: 8C32013B
md5: b74672d4795f57a86b5ffdcc70bc5230
name: qp.exe
sha1: 79d439bd62c0937152baa48b0d943bc2a310c58d
sha256: 95d9e43daf982309dbe4d50dfac4a6667a16586573fd3ba4e8cf019a0fba3f35
sha512: f06633a8d6f7f9d701581a9e743e10fa31bf8890eabccf7fa3078dc671c57fbdd744c9228a9b328c6fec50e707e92e4a8461978dc1cd5e5a067562cd337b801d
ssdeep: 98304:9e1aO8bX2W7UJCc5Z88NYRBNOy4V5SJBAUZLBn5Dx:9e1c2WLc6LmIJVVnj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.3.3.7
CompanyName: Heallox Corp.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.3.3.7
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Heur.SEPhish.2 also known as:

BkavW32.WintaskLTE.Trojan
DrWebTrojan.KillFiles.17845
MicroWorld-eScanGen:Heur.SEPhish.2
FireEyeGeneric.mg.b74672d4795f57a8
CAT-QuickHealTrojan.Dynamer.D9
Qihoo-360Win32/Trojan.54c
McAfeeGeneric PWS.ya
MalwarebytesHackTool.Agent
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusPassword-Stealer ( 0047e7de1 )
BitDefenderGen:Heur.SEPhish.2
K7GWPassword-Stealer ( 0047e7de1 )
Cybereasonmalicious.4795f5
TrendMicroTROJ_GEN.R057C0PCT20
F-ProtW32/AccPhish.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Bancos.ABHY
APEXMalicious
AvastWin32:Agent-AQQM [Trj]
ClamAVWin.Trojan.Agent-319001
GDataGen:Heur.SEPhish.2
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.KillFiles.exivvy
TencentMalware.Win32.Gencirc.10b07807
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoTrojWare.Win32.PSW.AccPhish.E@4ldh0q
F-SecureTrojan.TR/PHP.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.SEPhish.2 (B)
IkarusTrojan.PHP
CyrenW32/AccPhish.A.gen!Eldorado
JiangminTrojan/PSW.VKont.pq
WebrootW32.Rogue.Gen
AviraTR/PHP.Gen
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Win-Trojan/Accphish.6955773
Acronissuspicious
VBA32TrojanPSW.PHP.AccPhish
ALYacGen:Heur.SEPhish.2
MAXmalware (ai score=100)
Ad-AwareGen:Heur.SEPhish.2
PandaTrj/CI.A
ZonerTrojan.Win32.8863
TrendMicro-HouseCallTROJ_GEN.R057C0PCT20
RisingTrojan.Generic@ML.100 (RDML:FTcDr8zPGk5hz+yWZMtfWg)
YandexTrojan.PHP!PbMJa9j83Ec
SentinelOneDFI – Malicious PE
FortinetW32/AccPhish.EU!tr.pws
AVGWin32:Agent-AQQM [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan-PSW.PHP.AccPhish.eu

How to remove Heur.SEPhish.2?

Heur.SEPhish.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment