Malware

JS.Heur.Bomber.1.A19637EC.Gen (B) (file analysis)

Malware Removal

The JS.Heur.Bomber.1.A19637EC.Gen (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What JS.Heur.Bomber.1.A19637EC.Gen (B) virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine JS.Heur.Bomber.1.A19637EC.Gen (B)?


File Info:

crc32: F678B4E5
md5: 31c153af18518eb1554971bb0e39a90f
name: upload_file
sha1: ef50ade88e947cb7e88526e583235ee94417b41c
sha256: c1762c0acb5d99a17b7fe711c9320ec24e688a5cc5b88cd7425cba02ea94e005
sha512: e021633fec6036dd55d09f33d784303c7f0afb033d402b44f95cf772843ee2490ce32d0aab069b703097fb3c8bc8edc325db5e42071e3ca0e5b47bdb317afb6e
ssdeep: 768:4u4Bpq9OxbwbceYO4Bzz1h2oX9UI+jWckV2ZA8QQ0nItejELLHKvyhfmd:4VBpuOxbuQZ+TjkV2Zz0nIcjELcyho
type: Microsoft OOXML

Version Info:

0: [No Data]

JS.Heur.Bomber.1.A19637EC.Gen (B) also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanJS.Heur.Bomber.1.A19637EC.Gen
FireEyeJS.Heur.Bomber.1.A19637EC.Gen
CAT-QuickHealO97M.Downloader.39631
McAfeeExploit-GBY!BBDE7B890794
BitDefenderJS.Heur.Bomber.1.A19637EC.Gen
CyrenPP97M/Agent.KY.gen!Eldorado
SymantecTrojan.Gen.NPE
AvastScript:SNH-gen [Trj]
KasperskyHEUR:Trojan-Dropper.MSOffice.SDrop.gen
AlibabaTrojan:Win32/MalDoc.ali1000146
NANO-AntivirusTrojan.Script.ExpKit.fbenub
ViRobotXLS.Z.CVE-2017-1188.54456
AegisLabHacktool.MSOffice.Generic.3!c
TencentOffice.Exploit.Generic.Ljtx
Ad-AwareJS.Heur.Bomber.1.A19637EC.Gen
McAfee-GW-EditionBehavesLike.Downloader.qc
EmsisoftJS.Heur.Bomber.1.A19637EC.Gen (B)
GDataGeneric.Trojan.Agent.82TLZY
MAXmalware (ai score=80)
MicrosoftExploit:O97M/CVE-2017-11882.ARJ!MTB
ArcabitJS.Heur.Bomber.1.A19637EC.Gen
ZoneAlarmHEUR:Trojan-Dropper.MSOffice.SDrop.gen
AhnLab-V3Trojan/BIN.Maldoc
ZonerProbably Heur.W97Obfuscated
ESET-NOD32multiple detections
RisingMalware.ObfusVBA@ML.84 (VBA)
YandexTrojan.AvsMofer.bTd7ZX
IkarusWin32.Outbreak
FortinetVBA/Agent.615C!tr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.vbs.qexvmc.1

How to remove JS.Heur.Bomber.1.A19637EC.Gen (B)?

JS.Heur.Bomber.1.A19637EC.Gen (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment