Malware

Heur.Tomegun.21 (B) malicious file

Malware Removal

The Heur.Tomegun.21 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Tomegun.21 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the TrickBot malware family
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Heur.Tomegun.21 (B)?


File Info:

name: 36D3CC78BEC40F2DA7F5.mlw
path: /opt/CAPEv2/storage/binaries/794fff6a97c4caae592199b928130a7667c9440618a57e6449fd67c82f7b2779
crc32: 69CFDF94
md5: 36d3cc78bec40f2da7f5032de01d9592
sha1: 114e7cd7731b46206fcf09994852e36ac9746fc2
sha256: 794fff6a97c4caae592199b928130a7667c9440618a57e6449fd67c82f7b2779
sha512: 39f6e79f27d37752b50e3c0e95784afc077f8b799207c530b98b13172eeab78364dc3fa92c60f41073c516cb39c63e437e60fdb0603b72043f20dae0fc377223
ssdeep: 3072:ke49LXA+g8hXqNblcJ6CxagBSsrUZU2O+uir3DzxJeDe7EiQuBVHhF6:V4Rwe9AqJ5AsrUbwir3veDexlBVC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16834C076CBE1D6D8FFB54EF4B9344B19CCE239A72208F9C7D9802CD43165A94C663261
sha3_384: 21823cadf02b03652818aeb880f129b879a019d152174be78f065468d039d6c4a5a3b181a7719c701fa75caf0904a1ac
ep_bytes: e8db030000e936fdffff8bff558bec81
timestamp: 2018-05-23 07:45:02

Version Info:

0: [No Data]

Heur.Tomegun.21 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Yakes.4!c
AVGWin32:Malware-gen
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Tomegun.21
FireEyeGeneric.mg.36d3cc78bec40f2d
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Heur.Tomegun.21
ZillyaTrojan.GenericKD.Win32.145589
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055d5751 )
AlibabaTrojan:Win32/Yakes.5c6ce942
K7GWTrojan ( 0055d5751 )
Cybereasonmalicious.8bec40
CyrenW32/S-8c8c929c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GVNO
CynetMalicious (score: 99)
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Yakes.wkfy
BitDefenderGen:Heur.Tomegun.21
NANO-AntivirusTrojan.Win32.Yakes.fcmwpq
AvastWin32:Malware-gen
TencentWin32.Trojan.Yakes.Rqil
EmsisoftGen:Heur.Tomegun.21 (B)
F-SecureHeuristic.HEUR/AGEN.1316313
DrWebTrojan.DownLoader26.47121
VIPREGen:Heur.Tomegun.21
TrendMicroTROJ_GEN.R002C0PB523
McAfee-GW-EditionTrojan-FPRQ!36D3CC78BEC4
Trapminemalicious.moderate.ml.score
SophosMal/Inject-GH
GDataWin32.Trojan-Dropper.Agent.AIN
JiangminTrojan.Yakes.ztq
AviraHEUR/AGEN.1316313
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Yakes
XcitiumMalware@#su3h7jb6jvh6
ArcabitTrojan.Tomegun.21
ZoneAlarmTrojan.Win32.Yakes.wkfy
MicrosoftTrojan:Win32/TrickBot.G
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2543517
McAfeeTrojan-FPRQ!36D3CC78BEC4
VBA32Trojan.Yakes
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PB523
RisingTrojan.Totbrick!8.E0F0 (TFE:5:BdDyRVfXRBB)
IkarusTrojan.AD.Inject
FortinetW32/GenKryptik.CAPD!tr
BitDefenderThetaGen:NN.ZexaF.36196.oqW@aWa6PEei
DeepInstinctMALICIOUS

How to remove Heur.Tomegun.21 (B)?

Heur.Tomegun.21 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment