Trojan

What is “Trojan.Heur.BnKfrmrWaSmi”?

Malware Removal

The Trojan.Heur.BnKfrmrWaSmi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.BnKfrmrWaSmi virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan.Heur.BnKfrmrWaSmi?


File Info:

crc32: A3690F0D
md5: c454ca2849869967278d3a7c17ff84b2
name: 89t.exe
sha1: 5865215a98beaf042edc0da2114513496664e766
sha256: a50c6901f7bee081697d0ef812759d7ca7030ef11c5fff263dc8d6be7fa59325
sha512: 0882ea97b4162b0a9c0122790d0f9ee7893f09798ec053e576bebbbb20d4575962108b5e1927032e517423b50cfc91051d82994eea6f3523dbdb5b0f3e796c6e
ssdeep: 49152:0KrQrGn8fC5H4cUlMP3sKkaVRTewore/ETmwdPm1vuJwvwJlHAERNw1vzZEz9+z:0QQrGn8fC5H4lSsKk6Tewore/ECwdPmn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Heur.BnKfrmrWaSmi also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Trojan.Heur.BnKfrmrWaSmi
FireEyeGeneric.mg.c454ca2849869967
CAT-QuickHealTrojan.IGENERIC
Qihoo-360Win32/Backdoor.15f
McAfeeArtemis!C454CA284986
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0050bd1a1 )
BitDefenderGen:Trojan.Heur.BnKfrmrWaSmi
K7GWTrojan ( 0050bd1a1 )
Cybereasonmalicious.849869
BitDefenderThetaAI:Packer.BD4043941C
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R007H0CAM20
Paloaltogeneric.ml
GDataGen:Trojan.Heur.BnKfrmrWaSmi
KasperskyHEUR:Backdoor.Win32.Zegost.gen
AlibabaTrojan:Win32/Blouiroet.dc7f8f84
NANO-AntivirusTrojan.Win32.Blouiroet.fnpowl
TencentWin32.Trojan.Blouiroet.Swue
SophosMal/Generic-S
ComodoMalware@#1uwbj8t8u4i5m
F-SecureTrojan.TR/Crypt.FKM.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneDFI – Suspicious PE
Trapminesuspicious.low.ml.score
EmsisoftGen:Trojan.Heur.BnKfrmrWaSmi (B)
APEXMalicious
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan/Win32.Blouiroet
ArcabitTrojan.Heur.BnKfrmrWaSmi
ZoneAlarmHEUR:Backdoor.Win32.Zegost.gen
MicrosoftTrojan:Win32/Vigorf.A
MAXmalware (ai score=85)
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Delf.BBD
RisingTrojan.Blouiroet!8.ECDC (CLOUD)
IkarusTrojan.Delf.CoinMiner
eGambitUnsafe.AI_Score_89%
FortinetW32/Blouiroet!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Heur.BnKfrmrWaSmi?

Trojan.Heur.BnKfrmrWaSmi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment