Trojan

How to remove “Trojan.Heur.bnuafbPh7koi”?

Malware Removal

The Trojan.Heur.bnuafbPh7koi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.bnuafbPh7koi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Heur.bnuafbPh7koi?


File Info:

name: 906FCF9FA26BAE543587.mlw
path: /opt/CAPEv2/storage/binaries/601b57d81e38692621d7092241e60694dca4bfb24dd6591dc24630f197a307c6
crc32: 0001F689
md5: 906fcf9fa26bae5435872b30e85ca325
sha1: 9d021dc5741a6ea7bb8ec7b2585129d007832858
sha256: 601b57d81e38692621d7092241e60694dca4bfb24dd6591dc24630f197a307c6
sha512: f998c72cc6a53ea90639897cdbf74972ba10f27148920e4e2c7ddfcfda63efc790ab44dfd445180930dcb1937fa5babf9086a4d9a087a7078daa53606292e37c
ssdeep: 24576:qm4tKt3fPkoYWfcRnEii37fIAZKhJdwh2:l4tck4fcRnEii3zIFM2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197353307E06E7D17C7FD16379C188E0CA6047ECB4C106F796A65ABEF3818A266C8D187
sha3_384: ca421b018c2789c72f69589bbb33bc463ad7421726fc90821005a391aa22a4631aedea82bd3301e243925470ae66ba8e
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2021-07-24 00:10:18

Version Info:

Translation: 0x0409 0x04b0
CompanyName: PB
ProductName: PB
FileVersion: 1.00.0056
ProductVersion: 1.00.0056
InternalName: UPDATE ZEPO
OriginalFilename: UPDATE ZEPO.exe

Trojan.Heur.bnuafbPh7koi also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.mhnR
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.bnuafbPh7koi
FireEyeGeneric.mg.906fcf9fa26bae54
McAfeeArtemis!906FCF9FA26B
MalwarebytesRiskWare.GameHack
SangforTrojan.Win32.Gamehack.V017
K7AntiVirusUnwanted-Program ( 0058901d1 )
BitDefenderGen:Trojan.Heur.bnuafbPh7koi
K7GWUnwanted-Program ( 0058901d1 )
Cybereasonmalicious.fa26ba
ArcabitTrojan.Heur.bnuafbPh7koi
CyrenW32/ABRisk.XVUA-4353
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GameHack.FJC potentially unsafe
APEXMalicious
ClamAVWin.Malware.Zusy-9883587-0
KasperskyHEUR:Trojan.Win32.Generic
RisingHacktool.GameHack!8.59E (CLOUD)
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Trojan.Heur.bnuafbPh7koi
TrendMicroTROJ_GEN.R002C0XHA23
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.bnuafbPh7koi (B)
IkarusTrojan.Crypt
JiangminTrojan.Mucc.brs
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLRiskWare/Win32.Gamehack
XcitiumPacked.Win32.Krap.~IC@2o95zx
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:HackTool.Win32.GameHack.gen
GDataGen:Trojan.Heur.bnuafbPh7koi
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.bnuafbPh7koi
DeepInstinctMALICIOUS
VBA32Trojan.Wacatac
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0XHA23
TencentMalware.Win32.Gencirc.13ec2f6b
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.215809350.susgen
FortinetPossibleThreat.DU
BitDefenderThetaAI:Packer.26AE05A81C
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Heur.bnuafbPh7koi?

Trojan.Heur.bnuafbPh7koi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment