Malware

Malware.Heuristic.2012 (file analysis)

Malware Removal

The Malware.Heuristic.2012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.Heuristic.2012 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.Heuristic.2012?


File Info:

name: 0BA5843A30187EF62B0A.mlw
path: /opt/CAPEv2/storage/binaries/4d2a600b07a98a909c0f5be6c2490cc9e6a39fd90f41e9af326cec5f738b9c95
crc32: 786687FC
md5: 0ba5843a30187ef62b0adbbe599f5339
sha1: 5a922c6ac95f950c651c2dab2808e083ae86c630
sha256: 4d2a600b07a98a909c0f5be6c2490cc9e6a39fd90f41e9af326cec5f738b9c95
sha512: f98682b08b568331f72522f9e5c1b19286c68b09948ca967b1e194ea2749d2a040c7cb15082759b1ff922867f1ce78e17de310cc3b04e51dc94256812927b95b
ssdeep: 6144:keEmX26nmkVk03QG4nFXpEvos2rcR8K2wu2ANjrH1Kl:kryvVt3QhFdrcR8Ksb1Kl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F554BF137AE14857DABA0530CDE91BB7DEB8E8708ED2461393945F3D3D38A41DA06F26
sha3_384: 26bab41c7b4a8b5a1170c957fbff651a1972f074a0aabfd9568fca3704173016fd4e98c1a3b6fb9f9f89a2fa0b6853ed
ep_bytes: eb62558bec83ec188b7d108b750c33c0
timestamp: 2021-01-27 19:35:37

Version Info:

Comments: A small portable Windows program to prevent system shutdown, Standby, Hibernate, Turn Off and Restart
CompanyName: Nenad Hrg (SoftwareOK.com)
FileDescription: Don't Sleep
FileVersion: 7, 8, 9, 0
InternalName: Don'tSleep
LegalCopyright: Copyright © 2010-2021 Nenad Hrg SoftwareOK.com
LegalTrademarks:
OriginalFilename: DontSleep.exe
PrivateBuild:
ProductName: DontSleep
ProductVersion: 7, 8, 9, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.Heuristic.2012 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.72461733
FireEyeGeneric.mg.0ba5843a30187ef6
SkyhighArtemis
McAfeeArtemis!0BA5843A3018
MalwarebytesMalware.Heuristic.2012
SangforTrojan.Win32.Agent.V4y8
AlibabaTrojan:Win32/SaliCode.de9cae97
SymantecML.Attribute.HighConfidence
APEXMalicious
TrendMicro-HouseCallBackdoor.Win32.SWRORT.YXEDUZ
AvastWin32:SaliCode [Inf]
KasperskyTrojan.Win32.Shelm.anpj
BitDefenderTrojan.GenericKD.72461733
EmsisoftTrojan.GenericKD.72461733 (B)
GoogleDetected
TrendMicroBackdoor.Win32.SWRORT.YXEDUZ
Trapminemalicious.high.ml.score
SophosML/PE-A
JiangminTrojan.Shelma.cso
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D451ADA5
ZoneAlarmTrojan.Win32.Shelm.anpj
GDataTrojan.GenericKD.72461733
VBA32Malware-Cryptor.General.3
Cylanceunsafe
PandaTrj/Chgt.AD
IkarusTrojan.Win32.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rozena.AXP!tr
AVGWin32:SaliCode [Inf]
DeepInstinctMALICIOUS

How to remove Malware.Heuristic.2012?

Malware.Heuristic.2012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment