Malware

How to remove “Malware.Heuristic.2006”?

Malware Removal

The Malware.Heuristic.2006 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.Heuristic.2006 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.Heuristic.2006?


File Info:

name: 4B83CBE13EE2BBBF8007.mlw
path: /opt/CAPEv2/storage/binaries/0d84de5a7be15f9bcff3a2047e5c19ed7b083953454ea63bd12961f998f876c3
crc32: 50D1E931
md5: 4b83cbe13ee2bbbf80075f5cc92e7631
sha1: 53fa4da3d3e82317377693375ba8524452c85952
sha256: 0d84de5a7be15f9bcff3a2047e5c19ed7b083953454ea63bd12961f998f876c3
sha512: 110af6dc070eaeb4527a409cd1ad345703bbf62ac7636ffaf9e2a2355e2e0d4914a1cf9422dac1a1afbb9212bd1167f956bc625cbe6bda13c79bee0ebd5658f3
ssdeep: 1536:48OBLLV5Ayuc9c5bnf9dWe9rbSFRHjRK+nixbK3BPUX+22eOH:ZOtV5ep5bLN5SfdK+nikRM+22FH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4A3D0609D4440FDE633A53C6A3E73135651BEDBCB7639A7666802093D12F8E83607EB
sha3_384: 335706e602a3354c3c84cdc0a49a90bd5a8e6930683fc52a004fc468a2fb3b2b8908796b0a97ad49f72af6f3414ed8c1
ep_bytes: 558bec68ffffffff6891f10010689ff1
timestamp: 2010-04-15 10:33:13

Version Info:

FileDescription: Masktools Dynamic Link Library
FileVersion:
InternalName: Masktools 2.0
LegalCopyright: Copyright (C) 2005
OriginalFilename: mt_masktools.dll
ProductName: Masktools Dynamic Link Library
ProductVersion:
Translation: 0x0409 0x04b0

Malware.Heuristic.2006 also known as:

LionicTrojan.Win32.Generic.4!c
AVGWin32:Crypt-IMY [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.Hiloti.based.2
MicroWorld-eScanGen:Variant.Hiloti.3
SkyhighHiloti.gen.n
McAfeeHiloti.gen.n
MalwarebytesMalware.Heuristic.2006
VIPREGen:Variant.Hiloti.3
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Cimag.9aa8f995
K7GWTrojan ( 002686021 )
K7AntiVirusTrojan ( 002686021 )
BitDefenderThetaGen:NN.ZexaF.36802.gq0@auoDVtni
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Cimag.FX
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Hiloti-778
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Hiloti.3
NANO-AntivirusTrojan.Win32.Crypted.haqmi
AvastWin32:Crypt-IMY [Trj]
RisingTrojan.Hiloti!8.74D (TFE:3:0Vv83RP0cFT)
EmsisoftGen:Variant.Hiloti.3 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
ZillyaDownloader.Mufanom.Win32.24189
TrendMicroTROJ_HILOTI.SMAE
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4b83cbe13ee2bbbf
SophosMal/Hiloti-D
IkarusGen.Variant.Hiloti
WebrootTrojan:Win32/Hiloti
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Hiloti.gen!D
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.Hiloti.3
ViRobotTrojan.Win32.A.Downloader.98304.LW
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Hiloti.3
VaristW32/Hiloti.L.gen!Eldorado
AhnLab-V3Trojan/Win32.Hiloti.R1790
ALYacGen:Variant.Hiloti.3
VBA32BScope.Malware-Cryptor.Tip
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_HILOTI.SMAE
TencentWin32.Trojan.Generic.Cdhl
YandexTrojan.GenAsa!+fWThuu7VJg
SentinelOneStatic AI – Malicious PE
MaxSecureDownloader.Mufanom.aqda
FortinetW32/PackedHiloti.N!tr
Cybereasonmalicious.13ee2b
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Cimag.FX

How to remove Malware.Heuristic.2006?

Malware.Heuristic.2006 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment