Trojan

About “Trojan.Heur.RP.emKfbiSgX7mi” infection

Malware Removal

The Trojan.Heur.RP.emKfbiSgX7mi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.RP.emKfbiSgX7mi virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Trojan.Heur.RP.emKfbiSgX7mi?


File Info:

crc32: DEC49DEB
md5: 33805d14f9c737557477c52fad6d24e2
name: 33805D14F9C737557477C52FAD6D24E2.mlw
sha1: 1d2dbbb036ce3f57da948ff1a3063d0c7e8ee969
sha256: c4078ee15615267205901155b4fe8ed85afa0a788dc58c3e7d859f66e5d9873e
sha512: 98cc7545867ebaebd337d38d7043b24e2cc40df538fac6d17ad3f4b8116cab7e63ce74571489e3227e1be998f875db963c9d6cb435b496fe4865bb17259c51ce
ssdeep: 1536:LkdXRBV/N1WkWltDvbl3+O2kP+KabSxTjeQAYCqvlt1w:LIhBV/+3vR3VIKU9qvlt1w
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2011 by ValiantChaos
InternalName: VCBMH.exe
FileVersion: 133.1.0.3
ProductVersion: 133.1.0.3
FileDescription: Hack loader
OriginalFilename: VCBMH.exe
Translation: 0x0409 0x04b0

Trojan.Heur.RP.emKfbiSgX7mi also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Emkfaisgx.4!c
ALYacGen:Trojan.Heur.RP.emKfbiSgX7mi
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.4f9c73
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Spyware-gen [Spy]
BitDefenderGen:Trojan.Heur.RP.emKfbiSgX7mi
NANO-AntivirusTrojan.Win32.Ransom.clnqb
MicroWorld-eScanGen:Trojan.Heur.RP.emKfbiSgX7mi
Ad-AwareGen:Trojan.Heur.RP.emKfbiSgX7mi
ComodoMalware@#tfehi3idl11w
BitDefenderThetaAI:Packer.2EED841D1F
McAfee-GW-EditionBehavesLike.Win32.Upatre.lc
FireEyeGeneric.mg.33805d14f9c73755
EmsisoftGen:Trojan.Heur.RP.emKfbiSgX7mi (B)
eGambitUnsafe.AI_Score_80%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Heur.RP.emKfbiSgX7mi
GDataGen:Trojan.Heur.RP.emKfbiSgX7mi
McAfeeArtemis!33805D14F9C7
MAXmalware (ai score=84)
YandexTrojan.GenAsa!8Q3GGoHVdpk
SentinelOneStatic AI – Malicious PE
AVGWin32:Spyware-gen [Spy]
Paloaltogeneric.ml

How to remove Trojan.Heur.RP.emKfbiSgX7mi?

Trojan.Heur.RP.emKfbiSgX7mi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment