Trojan

About “Trojan.Heur.GM.0100010902” infection

Malware Removal

The Trojan.Heur.GM.0100010902 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.GM.0100010902 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Heur.GM.0100010902?


File Info:

name: EF05F93A37C98DBEC921.mlw
path: /opt/CAPEv2/storage/binaries/17a1915ff427a844ff662ebf9fd901a2ddd28d3f8a1e4e1770b7e8fe5538e564
crc32: B90D8598
md5: ef05f93a37c98dbec9216c282b62fe04
sha1: 37446dc9732fcc2a25dda9e04bfcc98626946985
sha256: 17a1915ff427a844ff662ebf9fd901a2ddd28d3f8a1e4e1770b7e8fe5538e564
sha512: 8e310e33b6ac3e8678bfbfaa703401b373b0bbb3cc2859200cec9dca890854e377d1b144754c07bee6ce75350f199c1b50471df6caafa008a468cb052427723f
ssdeep: 768:Acx8R9vUHwDLSZQUTE1H63sxfOd0E/IiS+gBE5ZOdf/s:AlRpMYL7H63swLgUZN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C543747A7BE41DF2F3B78AB585F615C6B820746239C1786E009E4B480812F46EDF16DE
sha3_384: 0ea27a6392a8867066f075bc59ee35dc8eea6823caff07b90c2f0274fbf2767590016d64e30536d23433c0506afe6318
ep_bytes: 558bec83ec4456ff150c2040008bf08a
timestamp: 1992-06-01 23:54:04

Version Info:

0: [No Data]

Trojan.Heur.GM.0100010902 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Crypt.m2KH
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.GM.0100010902
ALYacGen:Trojan.Heur.GM.0100010902
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
AlibabaTrojanDownloader:Win32/Upatre.4c133f52
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/S-984c42b6!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.GM.0100010902
NANO-AntivirusTrojan.Win32.MlwGen.ddpqrb
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b0ec05
Ad-AwareGen:Trojan.Heur.GM.0100010902
EmsisoftGen:Trojan.Heur.GM.0100010902 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.DA@5iyglc
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PWS.Panda.7599
ZillyaDownloader.Upatre.Win32.67074
TrendMicroTROJ_UPATRE.SMN6
McAfee-GW-EditionBehavesLike.Win32.Dropper.qt
FireEyeGeneric.mg.ef05f93a37c98dbe
SophosML/PE-A + Mal/Zbot-QL
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.GM.0100010902
JiangminBackdoor/Androm.cvu
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2AE6732
ArcabitTrojan.Heur.GM.D5F60B96
MicrosoftTrojan:Win32/Zbot.svfs!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R268536
McAfeeGenericRXHF-QS!EF05F93A37C9
MAXmalware (ai score=85)
VBA32BScope.TrojanPSW.Panda
MalwarebytesMalware.AI.2456335957
TrendMicro-HouseCallTROJ_UPATRE.SMN6
RisingDownloader.Waski!8.184 (CLOUD)
YandexTrojan.GenAsa!8NvE1AUsOeo
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr.dldr
BitDefenderThetaAI:Packer.261445C01D
AVGWin32:Trojan-gen
Cybereasonmalicious.a37c98
PandaTrj/Genetic.gen

How to remove Trojan.Heur.GM.0100010902?

Trojan.Heur.GM.0100010902 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment