Trojan

What is “Trojan.Heur.JP.wmKfay0wzDai”?

Malware Removal

The Trojan.Heur.JP.wmKfay0wzDai is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.JP.wmKfay0wzDai virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Heur.JP.wmKfay0wzDai?


File Info:

name: 9A54653172C6171E4492.mlw
path: /opt/CAPEv2/storage/binaries/555677576e8e7b92ed1d84b798c49a51c23aa990580a3cddd15a6d68ef156b14
crc32: 3560F6E7
md5: 9a54653172c6171e4492ecf947138519
sha1: 4d0f516a5426651dd31bb5c4e0f514414be59ba9
sha256: 555677576e8e7b92ed1d84b798c49a51c23aa990580a3cddd15a6d68ef156b14
sha512: 4c9f326ea2c3c4903bba9d0e3ca6a8c888e92b5f2663fd35e3baa4ffafe2629fd787a5faf60039aa6a1ad359e4317cbf257c41e303b7fb3f35c06c9a961e55f3
ssdeep: 6144:LQEM4c6TX9t31uDSSqhDd/IIogQ6DAksmmF6ahBxLimmHRKyAItez:LQEMKDP1hXFPkTlDlfyA5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B27423D16F60E907E0B2467ED0DBDFB27165AC36A20607036990BD9FF833A893B554E4
sha3_384: f7cea4aef0fd96202301011c2a44db53e79fc3e70d30d13909e07557cde3f6f260edc15ad344ad18683faebad8a5cbc3
ep_bytes: 60be008048008dbe0090f7ff57eb0b90
timestamp: 2023-11-21 12:19:28

Version Info:

CompanyName: Holydol
FileDescription: Holydol Update
FileVersion: 1.2.5.0
InternalName: Update.exe
LegalCopyright: Copyright (C) 2023 Holydol.
OriginalFilename: Update.exe
ProductName: Update
ProductVersion: 1.2.5.0
Translation: 0x0409 0x04b0

Trojan.Heur.JP.wmKfay0wzDai also known as:

BkavW32.Common.ACD0F412
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur.JP.wmKfay0wzDai
FireEyeGen:Trojan.Heur.JP.wmKfay0wzDai
SkyhighRDN/Generic.dx
McAfeeRDN/Generic.dx
Cylanceunsafe
VIPREGen:Trojan.Heur.JP.wmKfay0wzDai
SangforTrojan.Win32.Agent.Vrck
AlibabaTrojan:Win32/Generic.d9490bf4
Cybereasonmalicious.a54266
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.JP.wmKfay0wzDai
AvastWin32:TrojanX-gen [Trj]
SophosMal/Generic-S
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.JP.wmKfay0wzDai (B)
GDataGen:Trojan.Heur.JP.wmKfay0wzDai
GoogleDetected
Antiy-AVLGrayWare/Win32.Cayunamer
ArcabitTrojan.Heur.JP.wmKfay0wzDai
VaristW32/ABRisk.PSDJ-8400
BitDefenderThetaAI:Packer.3C422CBE1F
ALYacGen:Trojan.Heur.JP.wmKfay0wzDai
MAXmalware (ai score=81)
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09KU23
RisingTrojan.Generic@AI.88 (RDML:joZDEVI2RWAfGznXFE5WlQ)
MaxSecureTrojan.Malware.221047446.susgen
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Trojan.Heur.JP.wmKfay0wzDai?

Trojan.Heur.JP.wmKfay0wzDai removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment