Trojan

Trojan.Heur.D.cmHfbiVab!j removal

Malware Removal

The Trojan.Heur.D.cmHfbiVab!j is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.D.cmHfbiVab!j virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Heur.D.cmHfbiVab!j?


File Info:

name: D7CAF512C412AC4EE1C3.mlw
path: /opt/CAPEv2/storage/binaries/9af11974925b5f7ce51831aee56b2ca7832f36760a8270b4125d29d88f843c7e
crc32: 2FF4923C
md5: d7caf512c412ac4ee1c32f76c87669ed
sha1: bbba9243230c0169eae0cc5551ffdc29d5d5d7d4
sha256: 9af11974925b5f7ce51831aee56b2ca7832f36760a8270b4125d29d88f843c7e
sha512: dce7c73f572536e504b1dac301f83436dde58e1166ad8b1fdd5120cb0e5b83e1e3884e0e1a042478c0f762b9576582bdfd6521705bc2b2650c89085535a8a8aa
ssdeep: 768:t23C4zd6wl2oVZ3NU6+qbs8ERJe4vzNT6oG57pHHIzniSfRZt+fkyR+i47v5ZF:t4HdYoVZ9UsdJmNLmHIzniSfrtu947BT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D603F187B92AC7AFE1E1F17C86A660D6F99C49434154630E1A6D931B3FCE7204B27227
sha3_384: a0de2d1f9ebbd61a97a89dbd01dfe64071784c085bec8dc0243921dd512fbaff9a228cf3b29e25ea9ad9c1fa454225d8
ep_bytes: 60be00e040008dbe0030ffff5783cdff
timestamp: 2005-10-08 14:49:49

Version Info:

0: [No Data]

Trojan.Heur.D.cmHfbiVab!j also known as:

LionicTrojan.Win32.Small.lggJ
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.D.cmHfbiVab!j
ClamAVWin.Downloader.Agent-31522
CAT-QuickHealTrojan.MauvaiseRI.S5264815
McAfeeGenericRXAA-AA!D7CAF512C412
MalwarebytesGeneric.Trojan.Downloader.DDS
ZillyaDownloader.Small.Win32.116047
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 00007c681 )
AlibabaMalware:Win32/km_28efb71.None
K7GWTrojan-Downloader ( 00007c681 )
Cybereasonmalicious.2c412a
VirITTrojan.Win32.Agent.QY
CyrenW32/new-malware!Maximus
SymantecInfostealer
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.KW
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Small.cca
BitDefenderGen:Trojan.Heur.D.cmHfbiVab!j
NANO-AntivirusTrojan.Win32.Small.bstqok
SUPERAntiSpywareTrojan.Agent/Gen-Small
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Agent.hhq
EmsisoftGen:Trojan.Heur.D.cmHfbiVab!j (B)
F-SecureDialer.DIAL/Dialer.Gen
DrWebTrojan.MulDrop14.3374
VIPREGen:Trojan.Heur.D.cmHfbiVab!j
TrendMicroTROJ_DLOADER.BMV
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d7caf512c412ac4e
SophosTroj/Small-FA
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Agent.BJZ
JiangminTrojanDownloader.Small.cou
AviraDIAL/Dialer.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan[Downloader]/Win32.Small
XcitiumTrojWare.Win32.TrojanDownloader.Small.CCA@g7nnm
ArcabitTrojan.Heur.D.cmHfbiVab!j
ViRobotTrojan.Win32.A.Downloader.39544[UPX]
ZoneAlarmTrojan-Downloader.Win32.Small.cca
MicrosoftTrojanDownloader:Win32/Small
GoogleDetected
AhnLab-V3Trojan/Win32.Downloader.R6541
Acronissuspicious
BitDefenderThetaAI:Packer.CB8518951D
ALYacGen:Trojan.Heur.D.cmHfbiVab!j
VBA32BScope.TrojanDownloader.Agent
Cylanceunsafe
PandaTrj/Downloader.FNJ
TrendMicro-HouseCallTROJ_DLOADER.BMV
RisingDownloader.Small!8.B41 (TFE:5:Qt9VUqHIoxK)
YandexTrojan.GenAsa!sH7xtZl+lhA
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Small.CCA!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Heur.D.cmHfbiVab!j?

Trojan.Heur.D.cmHfbiVab!j removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment