Trojan

Trojan.Heur.GZ.biWfbSHR37h removal guide

Malware Removal

The Trojan.Heur.GZ.biWfbSHR37h is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.GZ.biWfbSHR37h virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

securebestapp20.com
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine Trojan.Heur.GZ.biWfbSHR37h?


File Info:

crc32: 008F6B20
md5: e81f857bffd0269d9375b08354de3293
name: E81F857BFFD0269D9375B08354DE3293.mlw
sha1: 141b4bc53ae0d4ff5d292cd175cd687fd2f57290
sha256: 6d656f110246990d10fe0b0132704b1323859d4003f2b1d5d03f665c710b8fd3
sha512: fef47a12d63e2637493eaea7d0f0f3771297e79830dae46ad2556c7ff58886b7a88f0325be3cec6197e632e512d2dfcfd93bd0041d7ee78d1914fe4b4148441f
ssdeep: 768:nOTNOHMbSz8nOTTlewONXuhCKaUWCOcR:kNrC8nCRJOZuhCK3/Oc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Heur.GZ.biWfbSHR37h also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.GZ.biWfbSHR37h
McAfeeArtemis!E81F857BFFD0
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Trojan.Heur.GZ.biWfbSHR37h
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bffd02
ArcabitTrojan.Heur.GZ.biWfbSHR37h
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Gen.yke
AlibabaRansom:Win32/generic.ali2000010
NANO-AntivirusTrojan.Win32.PEPM.hyuxps
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Trojan.Heur.GZ.biWfbSHR37h
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.PEPM.Gen
DrWebTrojan.Encoder.32740
ZillyaTrojan.Filecoder.Win32.16393
TrendMicroRansom_Gen.R011C0WJ620
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e81f857bffd0269d
EmsisoftGen:Trojan.Heur.GZ.biWfbSHR37h (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.PEPM.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Pynamer.B!rfn
ViRobotTrojan.Win32.Z.Agent.29696.BHV
ZoneAlarmTrojan-Ransom.Win32.Gen.yke
GDataGen:Trojan.Heur.GZ.biWfbSHR37h
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.9BC7ECB71E
VBA32BScope.Trojan.Diple
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Filecoder.ODE
TrendMicro-HouseCallRansom_Gen.R011C0WJ620
IkarusTrojan.Crypt
eGambitUnsafe.AI_Score_73%
FortinetW32/Gen.ODE!tr.ransom
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.3b2

How to remove Trojan.Heur.GZ.biWfbSHR37h?

Trojan.Heur.GZ.biWfbSHR37h removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment