Trojan

Trojan.Heur.D.cmHfb034VMb removal

Malware Removal

The Trojan.Heur.D.cmHfb034VMb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.D.cmHfb034VMb virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Heur.D.cmHfb034VMb?


File Info:

name: B9E2DDD8E573CF62584C.mlw
path: /opt/CAPEv2/storage/binaries/816e1d3ebfc4de2c968c4cf1cd1dcc21ca4ae1dd20b8b78adf6fb88f7414bb24
crc32: DD076CEE
md5: b9e2ddd8e573cf62584c8281780662f9
sha1: 8d8e9d1bbe780a734868724aaff28d1deec023b2
sha256: 816e1d3ebfc4de2c968c4cf1cd1dcc21ca4ae1dd20b8b78adf6fb88f7414bb24
sha512: aac92c2bb63bc07e6bf5c53bb720b3c4a6e6593b62cf469017923012a18ec1c3bbe5df68dfe7245f30b4f6833523494606df955c009ee865956aa4c1fa254e27
ssdeep: 768:ac3C4zd6wl2oVZ3eNU6+qbs8ERJe4vzNT6oG57pHHIzniSfRZt+fkyR+i4HvG0T:aOHdYoVZuNUsdJmNLmHIzniSfrtu94HF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10203F257B95AC7BEE1A5F13C8AD251D6F89C49434014630F1ABD971B3FCE7204A2B227
sha3_384: 76070876734cc9878151f8c8294251298391f5d3ff68fb90d2176f67845fe660531741d7194af0699079c3a66fb1fe6f
ep_bytes: 60be00e040008dbe0030ffff5783cdff
timestamp: 2005-10-08 14:39:38

Version Info:

0: [No Data]

Trojan.Heur.D.cmHfb034VMb also known as:

LionicTrojan.Win32.Small.lggJ
tehtrisGeneric.Malware
DrWebTrojan.MulDrop14.3374
MicroWorld-eScanGen:Trojan.Heur.D.cmHfb034VMb
FireEyeGeneric.mg.b9e2ddd8e573cf62
CAT-QuickHealTrojan.MauvaiseRI.S5264815
ALYacGen:Trojan.Heur.D.cmHfb034VMb
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Heur.D.cmHfb034VMb
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00558fe31 )
AlibabaMalware:Win32/km_28efb71.None
K7GWTrojan ( 00558fe31 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.A9F4A7D21D
VirITTrojan.Win32.Agent.QY
CyrenW32/new-malware!Maximus
SymantecInfostealer
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.KW
APEXMalicious
ClamAVWin.Downloader.Agent-31522
KasperskyTrojan-Downloader.Win32.Small.cca
BitDefenderGen:Trojan.Heur.D.cmHfb034VMb
NANO-AntivirusTrojan.Win32.Small.bstqok
ViRobotTrojan.Win32.Downloader.39592
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Agent.hhq
EmsisoftGen:Trojan.Heur.D.cmHfb034VMb (B)
F-SecureDialer.DIAL/Dialer.Gen
ZillyaDownloader.Small.Win32.116047
TrendMicroTROJ_DLOADER.BMV
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
Trapminemalicious.high.ml.score
SophosTroj/Small-FA
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Trojan-Downloader.Agent.BJZ
JiangminTrojanDownloader.Small.cou
WebrootW32.Malware.Gen
GoogleDetected
AviraDIAL/Dialer.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Downloader]/Win32.Small
XcitiumTrojWare.Win32.TrojanDownloader.Small.CCA@g7nnm
ArcabitTrojan.Heur.D.cmHfb034VMb
ZoneAlarmTrojan-Downloader.Win32.Small.cca
MicrosoftTrojanDownloader:Win32/Small
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R6541
Acronissuspicious
McAfeeGenericRXAA-AA!B9E2DDD8E573
VBA32BScope.TrojanDownloader.Agent
Cylanceunsafe
PandaTrj/Downloader.FNJ
TrendMicro-HouseCallTROJ_DLOADER.BMV
RisingDownloader.Small!8.B41 (TFE:5:Qt9VUqHIoxK)
YandexTrojan.GenAsa!sH7xtZl+lhA
SentinelOneStatic AI – Malicious PE
FortinetW32/Small.CCA!tr.dldr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.8e573c
DeepInstinctMALICIOUS

How to remove Trojan.Heur.D.cmHfb034VMb?

Trojan.Heur.D.cmHfb034VMb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment