Trojan

About “Trojan.Heur.omKfY2J2yhli” infection

Malware Removal

The Trojan.Heur.omKfY2J2yhli is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.omKfY2J2yhli virus can do?

  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a known Chimera ransomware decryption instruction / key file.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.omKfY2J2yhli?


File Info:

crc32: 74988F5D
md5: 8d41685da399735c457d1c24ff3a2bf9
name: 8D41685DA399735C457D1C24FF3A2BF9.mlw
sha1: 3e90d6bd3c069abfa7774bbdff384c16744cca4c
sha256: ea28829149747a1ab9c1ce7e8cd4192d034dc9edb24b1ff365e3adb250d77117
sha512: b6f1220ad2259f3d0a42445308e02b16436ba78b030deef2b732cf20ef8ba91353f7d4e6f3dfb066f861afbadedbb65ce891124f43cc27263e7c1dbad9cd77fe
ssdeep: 6144:5p8ATqCQG1FIz9w0LIFFt3u83yNhv++S0i3lMYvUY8EYJt+:bFqvuNFFt3p3yN1++q3lMYvUY8m
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2021
ProductVersion: 2.2.0.0
ProductName: FutureMoneySaver
FileVersion: 2.2.0.0
FileDescription: FutureMoneySaver
Translation: 0x040c 0x04e4

Trojan.Heur.omKfY2J2yhli also known as:

K7AntiVirusTrojan ( 0051918e1 )
DrWebTrojan.Encoder.33879
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.omKfY2J2yhli
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaRansom:Win32/generic.ali2000027
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.da3997
BaiduWin32.Adware.Generic.bo
CyrenW32/Trojan.PNZY-5293
ESET-NOD32a variant of Win32/Filecoder.ODM
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Encoder.mfk
BitDefenderGen:Trojan.Heur.omKfY2J2yhli
MicroWorld-eScanGen:Trojan.Heur.omKfY2J2yhli
Ad-AwareGen:Trojan.Heur.omKfY2J2yhli
SophosMal/Generic-S
BitDefenderThetaAI:Packer.CECE21601C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.8d41685da399735c
EmsisoftGen:Trojan.Heur.omKfY2J2yhli (B)
AviraTR/FileCoder.vsbwe
ArcabitTrojan.Heur.omKfY2J2yhli
AegisLabTrojan.Win32.Omkfy.4!c
ZoneAlarmTrojan-Ransom.Win32.Encoder.mfk
GDataGen:Trojan.Heur.omKfY2J2yhli
McAfeeArtemis!8D41685DA399
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.Gen
MalwarebytesRansom.SunCrypt
TrendMicro-HouseCallTROJ_GEN.R002H09DU21
RisingRansom.SunCrypt!1.D593 (CLOUD)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.ODM!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Heur.omKfY2J2yhli?

Trojan.Heur.omKfY2J2yhli removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment