Trojan

Trojan.Heur.KS.2 removal instruction

Malware Removal

The Trojan.Heur.KS.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.KS.2 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
nicovideo.jp
kaixin001.com
dempsre.in
webabado.in
plaveo.in

How to determine Trojan.Heur.KS.2?


File Info:

crc32: AF6D6B8E
md5: 4ec00beba09c23f4ba94d879c87c00c5
name: 4EC00BEBA09C23F4BA94D879C87C00C5.mlw
sha1: 44862e2b4528c11c45c07e8967162b9d6b03e034
sha256: 32e0e16181635f0b7f1fa485f8b6b1f48580a6b3099a77713dbe0fe01208d369
sha512: fd879f7ff0bcae679299fa26e5b147945a39da44a9fecdabd2b3b9a227add52e09fc22989a8588b1b365958b62de96b3ee35737ff66389d128153788e90beadc
ssdeep: 768:xDkfWemN0AQn7N6c2V7RfPrkHr8fxCU3imrGf+DmjpiMH19kF4x4UwNsQd4iSL:qfWeK0tgc2VVLpffqHjpp19VxRw6QLSL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Y DoctorWeb, Ltd., 1992-2011
InternalName: Dr.Web for Windows
FileVersion: 5.0.572.1152
CompanyName: ComponentOne LLC
LegalTrademarks:
Comments:
ProductName: Dr.Web for Windows La
ProductVersion: 5.0.572.1152
FileDescription: Dr.Web for Windows m 2011
OriginalFilename: FileProtector2011.exe
Translation: 0x0419 0x04e3

Trojan.Heur.KS.2 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.KS.2
FireEyeGeneric.mg.4ec00beba09c23f4
CAT-QuickHealTrojan.Renos.LX
McAfeeDownloader-CEW.x
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.hg!b1 (v)
SangforMalware
K7AntiVirusTrojan ( 002056d81 )
BitDefenderGen:Trojan.Heur.KS.2
K7GWTrojan ( 002056d81 )
Cybereasonmalicious.ba09c2
CyrenW32/FakeAlert.KK.gen!Eldorado
SymantecTrojan.FakeAV!gen48
TotalDefenseWin32/Renos.D!generic
APEXMalicious
AvastWin32:FakeAlert-XK [Trj]
ClamAVWin.Downloader.101919-1
KasperskyPacked.Win32.Krap.ih
AlibabaPacked:Win32/FakeAlert.70f93ba3
NANO-AntivirusTrojan.Win32.Krap.cukugz
ViRobotTrojan.Win32.Downloader.73728.MV
AegisLabHacktool.Win32.Krap.lmuI
RisingDownloader.Renos!8.1D0 (CLOUD)
Ad-AwareGen:Trojan.Heur.KS.2
SophosMal/Generic-R + Mal/FakeAV-IZ
ComodoTrojWare.Win32.TrojanDownloader.Codecpack.~agyw@2rtjev
F-SecureTrojan.TR/Dldr.Codecpa.mne
DrWebTrojan.DownLoader2.1012
ZillyaDownloader.CodecPack.Win32.12650
TrendMicroTROJ_FAKEAV.SMCP
McAfee-GW-EditionBehavesLike.Win32.Emotet.lh
EmsisoftGen:Trojan.Heur.KS.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.CodecPack.bxg
AviraTR/Dldr.Codecpa.mne
Antiy-AVLTrojan[Packed]/Win32.Krap
KingsoftWin32.Troj.Krap.ih.(kcloud)
MicrosoftTrojanDownloader:Win32/Renos.PT
SUPERAntiSpywareTrojan.Agent/Gen-FakeSoft[DrWeb]
ZoneAlarmPacked.Win32.Krap.ih
GDataGen:Trojan.Heur.KS.2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R2867
BitDefenderThetaAI:Packer.A20BC7AF14
ALYacGen:Trojan.Heur.KS.2
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDownloader.FakeAlert.BBT
TrendMicro-HouseCallTROJ_FAKEAV.SMCP
TencentMalware.Win32.Gencirc.10b64e84
YandexTrojan.DL.CodecPack!nc+oAUgl9UE
IkarusTrojan-Downloader.Win32.CodecPack
MaxSecureTrojan.Malware.1699297.susgen
FortinetW32/Krypt.QKV!tr
AVGWin32:FakeAlert-XK [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM20.1.6E3F.Malware.Gen

How to remove Trojan.Heur.KS.2?

Trojan.Heur.KS.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment