Trojan

Should I remove “Trojan.Heur.RP.amGfbqXpQMc”?

Malware Removal

The Trojan.Heur.RP.amGfbqXpQMc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.RP.amGfbqXpQMc virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Heur.RP.amGfbqXpQMc?


File Info:

name: FF8F2321B33064447496.mlw
path: /opt/CAPEv2/storage/binaries/f3d5752fe816634de27d5f42299cc8a24327d8b5db32e0f8ac9bce84ff376465
crc32: 722A6328
md5: ff8f2321b33064447496727b7994614d
sha1: 99248aef0e1586ad927e5bba60030c0171033836
sha256: f3d5752fe816634de27d5f42299cc8a24327d8b5db32e0f8ac9bce84ff376465
sha512: 4709f43f2de852b231ac6eb8432b01a5d121643a204df06a043b28c8e86b8dcbc6507e1ceeb5e7c9ebbe799178a61df7358da9689519ea362ea40677dcd27834
ssdeep: 96:ZfkEomMkDbEu1pHnuP30NXLAUFWfvKbNHW7I9Ls5tFgtNed:yp5k/nHHnumXL3WHKbNHW7I9w5Xd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AC16C53BA248F73DA8905713D66F76426D9106812EE3A836E285B6BDEF73800F85183
sha3_384: 22217585ce2d1a5e95d27a192dbc2cb563c1872d20c18c8dc6d0fa1caa121d903e3454fe19705ff3335d89aea05f54a6
ep_bytes: 60be009000108dbe0080ffff57eb0b90
timestamp: 2021-08-23 17:32:20

Version Info:

0: [No Data]

Trojan.Heur.RP.amGfbqXpQMc also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Amgfbqxpqmc.4!c
Elasticmalicious (high confidence)
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Sabsik.0fdc38aa
K7GWRiskware ( 0040eff71 )
BitDefenderThetaAI:Packer.674645B71E
CyrenW32/SecRisk-ProcessPatcher-Sml-
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.RP.amGfbqXpQMc
MicroWorld-eScanGen:Trojan.Heur.RP.amGfbqXpQMc
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazquxejchymhEjETGrqcCBi+)
Ad-AwareGen:Trojan.Heur.RP.amGfbqXpQMc
SophosMal/EncPk-AAT
ComodoApplicUnsaf.Win32.Renos.~FAT@1ruzpc
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RHO21
McAfee-GW-EditionRDN/Generic.grp
FireEyeGeneric.mg.ff8f2321b3306444
EmsisoftGen:Trojan.Heur.RP.amGfbqXpQMc (B)
IkarusTrojan.Hijacker
AviraTR/Hijacker.Gen
Antiy-AVLTrojan/Generic.ASMalwS.347D6E1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Heur.RP.amGfbqXpQMc
GDataGen:Trojan.Heur.RP.amGfbqXpQMc
AhnLab-V3Trojan/Win.Generic.C4415357
ALYacGen:Trojan.Heur.RP.amGfbqXpQMc
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002C0RHO21
YandexTrojan.Hijacker!Vc4BHRV6/Qg
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan.Heur.RP.amGfbqXpQMc?

Trojan.Heur.RP.amGfbqXpQMc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment