Trojan

Trojan.Heur.SFB.fnuaay7L0oobb malicious file

Malware Removal

The Trojan.Heur.SFB.fnuaay7L0oobb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.SFB.fnuaay7L0oobb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Heur.SFB.fnuaay7L0oobb?


File Info:

crc32: E73539CD
md5: 6b378e899828661159fcc294e5cee2a4
name: 6B378E899828661159FCC294E5CEE2A4.mlw
sha1: bef62b756a1e455a816413849978afa399acdb5c
sha256: 15ce7520a95e6273a53a9faee76f26020e6c2e61c3110d4f355069de6fa4980e
sha512: 955ec07a7e7907e3b7ba7ddba0483155c20c4ca77e8ea373bcbd898ec93c34f35b010a93779ccfcb0cf2b4820dc22ea665e329430a30425fb00d48cec18df44e
ssdeep: 24576:RHb0zm/Juhx/DuGGD5H9ETPcCjH6W+nP3I4Af2F+kJtNXvtd+vXb:l02HDbEICj94S2rjXvDMr
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: x4e00x8449x77e5x79cb x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x4e00x8449x77e5x79cb
Comments: x4ea4x6d41x7fa4xff1a107475777
ProductName: GameTool
ProductVersion: 1.0.0.0
FileDescription: GameTool
Translation: 0x0804 0x04b0

Trojan.Heur.SFB.fnuaay7L0oobb also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.SFB.fnuaay7L0oobb
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.998286
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Trojan.Heur.SFB.fnuaay7L0oobb
MicroWorld-eScanGen:Trojan.Heur.SFB.fnuaay7L0oobb
TencentWin32.Trojan.Symmi.Wozv
Ad-AwareGen:Trojan.Heur.SFB.fnuaay7L0oobb
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaAI:Packer.FE831CAF21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.6b378e8998286611
EmsisoftGen:Trojan.Heur.SFB.fnuaay7L0oobb (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_64%
Antiy-AVLTrojan/Generic.ASCommon.FA
KingsoftWin32.Malware.Heur_Generic.A.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.SFB.fnuaay7L0oobb
Acronissuspicious
McAfeeArtemis!6B378E899828
MAXmalware (ai score=99)
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/FlyStudio
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Heur.SFB.fnuaay7L0oobb?

Trojan.Heur.SFB.fnuaay7L0oobb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment