Trojan

How to remove “Trojan.Heur.anGfrHVGbbkOh”?

Malware Removal

The Trojan.Heur.anGfrHVGbbkOh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.anGfrHVGbbkOh virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.anGfrHVGbbkOh?


File Info:

crc32: C0EF8C8B
md5: 1f428193a9da0a36e691f0bbb0d7a545
name: 1F428193A9DA0A36E691F0BBB0D7A545.mlw
sha1: 82e61b40e7b1643f41cb410301e6973995905d98
sha256: 1e0721e30fda5b16cbd0a6ea60a0223d763dc6d8112a09f94cc9e9e33a135b68
sha512: 51340f34e534802c04b815fb718b0dd49b0dd0e9f74227dde41c2bbd1ea98b4989232dd39e59c5ccfe2706fc7feb78a8f54052d3fb757d4a58e98929a11efe66
ssdeep: 24576:0chirSm44UbA8IIgyMp/b0QsDwsm/6mtoi2plbJpPuNSGdRBYK:0cjmXDpt1bTsm/Bo3nRuRPeK
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Heur.anGfrHVGbbkOh also known as:

K7AntiVirusTrojan ( 004f829e1 )
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.anGfrHVGbbkOh
CylanceUnsafe
ZillyaTrojan.Banbra.Win32.13907
SangforTrojan.Win32.Banbra.buxin
AlibabaTrojanSpy:Win32/Banker.846e27b0
K7GWTrojan ( 004f829e1 )
Cybereasonmalicious.3a9da0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.AEAS
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Trojan.Agent-7405658-0
BitDefenderGen:Trojan.Heur.anGfrHVGbbkOh
NANO-AntivirusTrojan.Win32.Gypikonbased.egfalb
MicroWorld-eScanGen:Trojan.Heur.anGfrHVGbbkOh
TencentWin32.Trojan.Spy.Eadu
Ad-AwareGen:Trojan.Heur.anGfrHVGbbkOh
SophosGeneric ML PUA (PUA)
ComodoMalware@#238l842czxixx
BitDefenderThetaAI:Packer.F1CE222C1D
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
FireEyeGen:Trojan.Heur.anGfrHVGbbkOh
EmsisoftGen:Trojan.Heur.anGfrHVGbbkOh (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Banker.Banbra.lse
WebrootW32.Malware.Gen
AviraTR/Spy.1062912.3
eGambitUnsafe.AI_Score_55%
Antiy-AVLTrojan/Generic.ASMalwS.EEA5AA
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.anGfrHVGbbkOh
McAfeeArtemis!1F428193A9DA
MAXmalware (ai score=100)
VBA32TrojanBanker.Banbra
PandaGeneric Malware
YandexTrojan.GenAsa!PMlLS2pX/E0
IkarusTrojan-Banker.Win32.Banbra
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banbra.ANIS!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Trojan.Heur.anGfrHVGbbkOh?

Trojan.Heur.anGfrHVGbbkOh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment