Trojan

Trojan.Heur.cmGfXbYqQDl removal

Malware Removal

The Trojan.Heur.cmGfXbYqQDl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.cmGfXbYqQDl virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan.Heur.cmGfXbYqQDl?


File Info:

name: 9C4F3897A005DFF42A3F.mlw
path: /opt/CAPEv2/storage/binaries/270503d560c974ebdbbfabf369fa13a701aae0131b84c1256a375d9929e10880
crc32: E2026F49
md5: 9c4f3897a005dff42a3f94ad5062c666
sha1: b2b6b42a6235f21bbfa5a0da824da521b5405316
sha256: 270503d560c974ebdbbfabf369fa13a701aae0131b84c1256a375d9929e10880
sha512: 7c199a2ce6ba5aed2aad26c3206246e51e4832ea5c924b66af1fbe7e7c9b37e22fda102cd185c4b9a1bdcbf3330eb1f539504ae9ef015f535333ab388549526c
ssdeep: 768:Mj/97H4dOf/qIz0vSsB1ZQmUUs4+ruDBOdZrNzLqDEqINdm3PTQEzf2Idnbl:MjlN3qO5Y1Js44uDBOJzXvNk/UEBbl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F1302AD96217D11C4E27033467474B55247BACD0EA50E060B83E2C368F6DEC76E5BDE
sha3_384: fd33322d15d0c631503da4bcbd9aae15dc59140a5913ab4145f875b149c3e2604c70f5cb5b0becc8f2691af3d4f1731f
ep_bytes: 60be154041008dbeebcffeff5783cdff
timestamp: 2022-08-23 18:56:13

Version Info:

0: [No Data]

Trojan.Heur.cmGfXbYqQDl also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Trojan.Heur.cmGfXbYqQDl
FireEyeGeneric.mg.9c4f3897a005dff4
McAfeeGenericRXJG-WZ!F795B9B69AC8
CylanceUnsafe
VIPREGen:Trojan.Heur.cmGfXbYqQDl
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.7a005d
BaiduWin32.Trojan.Kryptik.aak
SymantecPacked.Generic.508
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GHGG
APEXMalicious
ClamAVWin.Packer.Hyperion-1
BitDefenderGen:Trojan.Heur.cmGfXbYqQDl
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Trojan.Heur.cmGfXbYqQDl
EmsisoftGen:Trojan.Heur.cmGfXbYqQDl (B)
DrWebTrojan.Packed2.42612
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.cmGfXbYqQDl
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C687
ArcabitTrojan.Heur.cmGfXbYqQDl
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32TrojanDownloader.Banload
ALYacGen:Trojan.Heur.cmGfXbYqQDl
MAXmalware (ai score=80)
MalwarebytesMalware.Heuristic.1003
RisingDownloader.Waski!8.184 (TFE:3:hg4uYaRqhIN)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CGVS!tr
BitDefenderThetaAI:Packer.489CFBF91B
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Heur.cmGfXbYqQDl?

Trojan.Heur.cmGfXbYqQDl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment