Trojan

Trojan.Heur.GM.01C0004D20 removal instruction

Malware Removal

The Trojan.Heur.GM.01C0004D20 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.GM.01C0004D20 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

How to determine Trojan.Heur.GM.01C0004D20?


File Info:

name: 95376B43FF0AB0FC7F07.mlw
path: /opt/CAPEv2/storage/binaries/38bd2b630eca60049b85710ccfdebeedc366f81669d96152ea67e61c0f8b3df5
crc32: 08475161
md5: 95376b43ff0ab0fc7f07757ca0a5a560
sha1: b038d8c04516d60a4487b8377bea91ea8b173ba9
sha256: 38bd2b630eca60049b85710ccfdebeedc366f81669d96152ea67e61c0f8b3df5
sha512: a130b7f2aafe90cdf3e72c51a52e4cd4f9b3472f119438a17b7807d992dfb0d0f2e20acd97e533f52285ca8fbffba3e5eb5c8dde85530729992cf8709a043696
ssdeep: 6144:DhcCXXd/kFzxGE3i/DmCRxcinoEOcUKCS+915KODFW3U4muf:OCXtsFg82DmCMinXDPA5FDw3U4muf
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10374F1C05B5033E3C56B4770E7F1B6B57770B052AB72A37A00A0C5AB8F52542FDA629E
sha3_384: db68a8b525d574276687d70e4d6ad047b88e8e0f6ae81ee2520bbb54bbef9c73d5f5b056392fe417a93a6a5820370f07
ep_bytes: eb03bc9d8d50eb02833ee815000000eb
timestamp: 2020-12-22 19:59:46

Version Info:

0: [No Data]

Trojan.Heur.GM.01C0004D20 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Trojan.Heur.GM.01C0004D20
FireEyeGeneric.mg.95376b43ff0ab0fc
CylanceUnsafe
Cybereasonmalicious.3ff0ab
BitDefenderThetaAI:Packer.36D895F91D
Elasticmalicious (high confidence)
BitDefenderGen:Trojan.Heur.GM.01C0004D20
APEXMalicious
Ad-AwareGen:Trojan.Heur.GM.01C0004D20
EmsisoftGen:Trojan.Heur.GM.01C0004D20 (B)
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
GDataGen:Trojan.Heur.GM.01C0004D20
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.GM.01C0004D20
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingTrojan.Generic@AI.97 (RDMK:cmRtazr/ySAoraf4XPKZR0wgciKZ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Heur.GM.01C0004D20?

Trojan.Heur.GM.01C0004D20 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment