Trojan

Should I remove “Trojan.Heur.RP.biXfb05eHSpb”?

Malware Removal

The Trojan.Heur.RP.biXfb05eHSpb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.RP.biXfb05eHSpb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Heur.RP.biXfb05eHSpb?


File Info:

crc32: 50426D38
md5: cb2c50fcadf2015a6d3edb8c840ce798
name: CB2C50FCADF2015A6D3EDB8C840CE798.mlw
sha1: 50da9519bbc20e14b0af770c2956587d798bfa72
sha256: b0e639d723f6f93c56630019c81f9fd8b0b53e90e71a37c618712cb874f06ca2
sha512: e515b6945859863033d3567d6b5f55d60b577eed36d50e6a00f275d8f7433c15895966ba36cfd64d0b88e57f98ae89d6cfd168c5c6cdbe124d698821fa07c975
ssdeep: 768:vPlWm9zAPoefi/zhJYW2Q6quvywII80Xne8x:vPlJzAg4SzhJYN3tywQcVx
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Trojan.Heur.RP.biXfb05eHSpb also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( f15000051 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.25466
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.RP.biXfb05eHSpb
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaAdWare:Win32/Banload.086c7253
K7GWRiskware ( f15000051 )
Cybereasonmalicious.cadf20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PCD
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Spyware.84317-2
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Heur.RP.biXfb05eHSpb
NANO-AntivirusTrojan.Win32.OnLineGames.cymmm
MicroWorld-eScanGen:Trojan.Heur.RP.biXfb05eHSpb
TencentWin32.Trojan-gamethief.Onlinegames.Syhw
Ad-AwareGen:Trojan.Heur.RP.biXfb05eHSpb
SophosMal/Dropper-O
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
BitDefenderThetaAI:Packer.436CB64F1F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0RGH21
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeGeneric.mg.cb2c50fcadf2015a
EmsisoftGen:Trojan.Heur.RP.biXfb05eHSpb (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.OnLineGames.cefp
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.RP.biXfb05eHSpb
TACHYONTrojan/W32.Small.28872.H
AhnLab-V3Trojan/Win32.OnlineGameHack.R52048
McAfeeGenericRXAA-FA!CB2C50FCADF2
MAXmalware (ai score=100)
VBA32BScope.Trojan-Dropper.Injector
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R067C0RGH21
YandexTrojan.DR.Agent!bTBcO3BaSF0
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.3257124.susgen
FortinetW32/Onlinegames.O!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Heur.RP.biXfb05eHSpb?

Trojan.Heur.RP.biXfb05eHSpb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment