Trojan

About “Trojan.Heur.JP.toIfaS66J8ej” infection

Malware Removal

The Trojan.Heur.JP.toIfaS66J8ej is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.JP.toIfaS66J8ej virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Heur.JP.toIfaS66J8ej?


File Info:

name: 18ABE937D20076E8C40D.mlw
path: /opt/CAPEv2/storage/binaries/373d1d2b4ad0d129a35ffd6046225cf165a30894a392d4bd499e65b61266ba2f
crc32: 7724AFE8
md5: 18abe937d20076e8c40d3d9591b6716c
sha1: 4fcb39921f799aaa92f00adba24a714ed5c4193a
sha256: 373d1d2b4ad0d129a35ffd6046225cf165a30894a392d4bd499e65b61266ba2f
sha512: 0de253c3116d326c7e430bcfe306726d9052ab12abc8fb8ea9dbb0935e91a3c80262f56e9af964770a399c9d4d62cb7d2c3d0022ae0bbc8413f786446fbc1974
ssdeep: 49152:ou+aHg1mnajkZ3lfMVRIvmiz3PoETht2U87vqFddOF4TaQPwwFIOV3qv9yk63+B5:ou+aHg1mnajlVivm8PHTH2U87g3g4Taj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFB52322044424B8FB642D38F61CF4EA1A073D5B0C9475266C17F5E417BBBE9EAE3A47
sha3_384: aa19a0a6d78c46d1eb77fe63f2d1ec322f82cb6d47c857e1167774c0cfa57b859a1cd4d3aff71e6738d3b62fcc623e7b
ep_bytes: 60be001043008dbe0000fdff5783cdff
timestamp: 2018-06-06 03:47:36

Version Info:

0: [No Data]

Trojan.Heur.JP.toIfaS66J8ej also known as:

MicroWorld-eScanGen:Trojan.Heur.JP.toIfaS66J8ej
FireEyeGeneric.mg.18abe937d20076e8
McAfeeArtemis!18ABE937D200
Cylanceunsafe
K7AntiVirusTrojan ( 005a41721 )
K7GWTrojan ( 005a41721 )
Cybereasonmalicious.7d2007
BitDefenderThetaAI:Packer.9FE79EAF1F
VirITPUP.Win32.Generic.R
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BJW
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xawvyt
BitDefenderGen:Trojan.Heur.JP.toIfaS66J8ej
NANO-AntivirusTrojan.Win32.KryptikAGen.jvvqmi
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Trojan.Heur.JP.toIfaS66J8ej (B)
VIPREGen:Trojan.Heur.JP.toIfaS66J8ej
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Heur.JP.toIfaS66J8ej
JiangminTrojan.Generic.eljwd
MAXmalware (ai score=87)
ArcabitTrojan.Heur.JP.toIfaS66J8ej
ZoneAlarmTrojan.Win32.Agent.xawvyt
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R569846
ALYacGen:Trojan.Heur.JP.toIfaS66J8ej
MalwarebytesMalware.AI.3841723277
TrendMicro-HouseCallTROJ_GEN.R03BH0CDT23
RisingTrojan.Agent!8.B1E (TFE:5:4Bitv4m9pVU)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BJW!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (D)

How to remove Trojan.Heur.JP.toIfaS66J8ej?

Trojan.Heur.JP.toIfaS66J8ej removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment