Trojan

Should I remove “Trojan.Heur.hi3frDAUi!mib”?

Malware Removal

The Trojan.Heur.hi3frDAUi!mib is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.hi3frDAUi!mib virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Disables host Context Menu in Taskbar and Start
  • Attempts to disable or modify Explorer Folder Options
  • Disables host Power options (shutdown, logoff, lock, change password)
  • Attempts to disable or modify the Run command from the Start menu and the New Task (Run) command from Task Manager
  • Attempts to disable System Restore
  • Attempts to modify or disable Security Center warnings
  • Creates a known Scarab-Dharma ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Heur.hi3frDAUi!mib?


File Info:

name: 659A3879C041C59D7E1C.mlw
path: /opt/CAPEv2/storage/binaries/b1ce314a9c84e94188e0ce327f9f9d268227581dd28c53770690c2794d0ba808
crc32: 7396E731
md5: 659a3879c041c59d7e1c67d183bd2a49
sha1: 5e936beee6b8ecb6318f93d8a69ea633476d321b
sha256: b1ce314a9c84e94188e0ce327f9f9d268227581dd28c53770690c2794d0ba808
sha512: 98049ae4b9fe5fd1859a54efc2fb34649f0f5501f07116fc2b5855a5f1c2047b7c0bdfc726433944276301594d65977c01d6e4d59aa9fc0eec9a0fec8257330a
ssdeep: 1536:1LHIlfH7Q6qRBwWa2qxQFZA+j6wWw+9yLHIlfH7Q6qRBwWa2qxQFZA+j6R:1oS6qcWjqazp6hRcoS6qcWjqazp6R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154C3E0437222841DF7A09978C9434A5E829A3F328917B87B64593F3B3E3C1D76F91362
sha3_384: 4d7fcf9422a92b883a555669e31b11a5610e4bf1ac7cd246fde6e146e42a94aeaa184041500236c5cae30c6356e07021
ep_bytes: b840b846005064ff3500000000648925
timestamp: 2008-05-16 04:00:12

Version Info:

Translation: 0x0409 0x04b0
ProductName: BlackHole
FileVersion: 0.00
ProductVersion: 0.00
InternalName: BlackHole
OriginalFilename: BlackHole.exe

Trojan.Heur.hi3frDAUi!mib also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.hi3frDAUi!mib
FireEyeGeneric.mg.659a3879c041c59d
ALYacGen:Trojan.Heur.hi3frDAUi!mib
CylanceUnsafe
VIPREWorm.Win32.Autorun.efi (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f6141 )
K7GWTrojan ( 0040f6141 )
Cybereasonmalicious.9c041c
BitDefenderThetaAI:Packer.2E0724EF1D
VirITWorm.Win32.Generic.AJRP
CyrenW32/Worm.FRMW-9132
ESET-NOD32Win32/AutoRun.VB.YF
BaiduWin32.Worm.VB.k
ClamAVLegacy.Trojan.Agent-1388588
KasperskyWorm.Win32.AutoRun.efi
BitDefenderGen:Trojan.Heur.hi3frDAUi!mib
NANO-AntivirusTrojan.Win32.AutoRun.bntuw
APEXMalicious
TencentWorm.Win32.Autorun.aax
EmsisoftGen:Trojan.Heur.hi3frDAUi!mib (B)
ComodoWorm.Win32.Autorun.~NIK@1k3g94
DrWebWin32.HLLW.Autoruner1.34449
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosML/PE-A + Mal/VB-F
IkarusEmail-Worm.Win32.Brontok
JiangminWorm/AutoRun.ikr
AviraTR/Crypt.CFI.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.18D54D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotWorm.Win32.Autorun.71680.J
ZoneAlarmWorm.Win32.AutoRun.efi
GDataGen:Trojan.Heur.hi3frDAUi!mib
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.AutoRun.R50265
McAfeeGenericRXAA-AA!659A3879C041
VBA32Trojan.VB.gen
MalwarebytesMalware.AI.1217022996
AvastWin32:Trojan-gen
RisingWorm.VBInjectEx!1.99E6 (RDMK:cmRtazpL7rhUJlmjTl3+thC/MRvT)
YandexTrojan.GenAsa!6rQOIinMt0s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.43B5!tr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Heur.hi3frDAUi!mib?

Trojan.Heur.hi3frDAUi!mib removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment