Categories: Trojan

About “Trojan.Heur.omKfY2J2yhli” infection

The Trojan.Heur.omKfY2J2yhli is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.omKfY2J2yhli virus can do?

  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a known Chimera ransomware decryption instruction / key file.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.omKfY2J2yhli?


File Info:

crc32: 74988F5Dmd5: 8d41685da399735c457d1c24ff3a2bf9name: 8D41685DA399735C457D1C24FF3A2BF9.mlwsha1: 3e90d6bd3c069abfa7774bbdff384c16744cca4csha256: ea28829149747a1ab9c1ce7e8cd4192d034dc9edb24b1ff365e3adb250d77117sha512: b6f1220ad2259f3d0a42445308e02b16436ba78b030deef2b732cf20ef8ba91353f7d4e6f3dfb066f861afbadedbb65ce891124f43cc27263e7c1dbad9cd77fessdeep: 6144:5p8ATqCQG1FIz9w0LIFFt3u83yNhv++S0i3lMYvUY8EYJt+:bFqvuNFFt3p3yN1++q3lMYvUY8mtype: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2021ProductVersion: 2.2.0.0ProductName: FutureMoneySaverFileVersion: 2.2.0.0FileDescription: FutureMoneySaverTranslation: 0x040c 0x04e4

Trojan.Heur.omKfY2J2yhli also known as:

K7AntiVirus Trojan ( 0051918e1 )
DrWeb Trojan.Encoder.33879
Cynet Malicious (score: 100)
ALYac Gen:Trojan.Heur.omKfY2J2yhli
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (W)
Alibaba Ransom:Win32/generic.ali2000027
K7GW Trojan ( 0051918e1 )
Cybereason malicious.da3997
Baidu Win32.Adware.Generic.bo
Cyren W32/Trojan.PNZY-5293
ESET-NOD32 a variant of Win32/Filecoder.ODM
APEX Malicious
Avast FileRepMalware
Kaspersky Trojan-Ransom.Win32.Encoder.mfk
BitDefender Gen:Trojan.Heur.omKfY2J2yhli
MicroWorld-eScan Gen:Trojan.Heur.omKfY2J2yhli
Ad-Aware Gen:Trojan.Heur.omKfY2J2yhli
Sophos Mal/Generic-S
BitDefenderTheta AI:Packer.CECE21601C
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
FireEye Generic.mg.8d41685da399735c
Emsisoft Gen:Trojan.Heur.omKfY2J2yhli (B)
Avira TR/FileCoder.vsbwe
Arcabit Trojan.Heur.omKfY2J2yhli
AegisLab Trojan.Win32.Omkfy.4!c
ZoneAlarm Trojan-Ransom.Win32.Encoder.mfk
GData Gen:Trojan.Heur.omKfY2J2yhli
McAfee Artemis!8D41685DA399
MAX malware (ai score=85)
VBA32 BScope.TrojanRansom.Gen
Malwarebytes Ransom.SunCrypt
TrendMicro-HouseCall TROJ_GEN.R002H09DU21
Rising Ransom.SunCrypt!1.D593 (CLOUD)
Ikarus Trojan-Ransom.FileCrypter
Fortinet W32/Filecoder.ODM!tr
AVG FileRepMalware
Paloalto generic.ml

How to remove Trojan.Heur.omKfY2J2yhli?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

About “TrojanDownloader:Win32/Seimon.D” infection

The TrojanDownloader:Win32/Seimon.D is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

VHO:Trojan.Win32.Copak.cpulx removal tips

The VHO:Trojan.Win32.Copak.cpulx is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Virus:Win32/Jadtre.B information

The Virus:Win32/Jadtre.B is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

Generic.Dialer.067D8B6E (file analysis)

The Generic.Dialer.067D8B6E is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

How to remove “Trojan:Win32/Vbclone.RPX!MTB”?

The Trojan:Win32/Vbclone.RPX!MTB is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

Malware.AI.2511406519 removal tips

The Malware.AI.2511406519 is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago