Trojan

Trojan.Heur.GM.01C0046C20 (B) (file analysis)

Malware Removal

The Trojan.Heur.GM.01C0046C20 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.GM.01C0046C20 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.GM.01C0046C20 (B)?


File Info:

crc32: D6E9C47D
md5: 5679f8a54271b5e7d3fdaf08579e1b6a
name: 5679F8A54271B5E7D3FDAF08579E1B6A.mlw
sha1: 28f9a4c861659e2c0d5abe866524c06f98a6180f
sha256: d3722c83e2ad6894748e9590cd02d5461351396ce24abb858cd696eba89a0054
sha512: 3ee1d69cf947f9e70a4fb0eeb1aba0e3e22616b9d4a97f5d365f2cc770ee6cb00c2d9bff93d2c6f15d50230958b97c57a42acace550b14d4ed5d458b33440ac5
ssdeep: 12288:pVnnNw7Y7qzo4E+xHFsiLAfaUPLPI1Uxfc7bRwv1JRAXRIoPTr1nt8v:XnnNsJo4EWHFLgHPzI/bRcTRboPTr1n
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Trojan.Heur.GM.01C0046C20 (B) also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.GM.01C0046C20
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.54271b
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyVHO:Trojan-Ransom.Win32.Blocker.gen
BitDefenderGen:Trojan.Heur.GM.01C0046C20
MicroWorld-eScanGen:Trojan.Heur.GM.01C0046C20
Ad-AwareGen:Trojan.Heur.GM.01C0046C20
SophosML/PE-A
BitDefenderThetaAI:Packer.6C1EED371D
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.5679f8a54271b5e7
EmsisoftGen:Trojan.Heur.GM.01C0046C20 (B)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASMalwS.23976D4
MicrosoftExploit:Win32/ShellCode!ml
GDataGen:Trojan.Heur.GM.01C0046C20
AhnLab-V3Malware/Gen.Generic.C2825709
McAfeeArtemis!5679F8A54271
MAXmalware (ai score=96)
VBA32BScope.Trojan.Tiggre
RisingTrojan.Generic@ML.90 (RDML:94VhEeg0/mOicLlmwrzEfA)
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Heur.GM.01C0046C20 (B)?

Trojan.Heur.GM.01C0046C20 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment