Trojan

Trojan.Heur.smeirv44zpeby information

Malware Removal

The Trojan.Heur.smeirv44zpeby is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.smeirv44zpeby virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid

How to determine Trojan.Heur.smeirv44zpeby?


File Info:

name: 7C0E88EC87F181EEE75B.mlw
path: /opt/CAPEv2/storage/binaries/3767db5ab219094f93ba19642ed7c7ab7a9fe8c589a7bc31ec38b345343e1e71
crc32: 5A9EC460
md5: 7c0e88ec87f181eee75b0389fa385e47
sha1: c3ceb3f6f07298fa3f278bd602a1a6c31e179ed5
sha256: 3767db5ab219094f93ba19642ed7c7ab7a9fe8c589a7bc31ec38b345343e1e71
sha512: daa69ac78e10b5e3c6263f3f240f369c89486815c890c845a20637293e4fbb7e9b14ace290371b4cac106026d21d3a8e617a542e155344063ca588ca3ebfb4b6
ssdeep: 6144:mgHeAxWRyYWHi1kkUU4bk/n/qopSjwYRoa0d3W5AGJzyu1v9Ln6KGQ5An6c7MO:mRyTSktU4g/n/t0EW5A0zyYvJwQ5ojMO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103544C37F1A1D437D2733578DC1B46B9A825BE112E2C248B6FE92D1C9F3978239281D6
sha3_384: ee6647fd0c5ccfbba42cb93a65e2122c01886a49cbf3c2b33dc9607c64bd2fd3da6a5e6ff89020b0311059a77f3a72f5
ep_bytes: 558bec81ecd4010000535657eb0c4578
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: WMI Performance Adapter Service
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: WmiApSrv.exe
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: WmiApSrv.exe
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 5.1.2600.2180
Translation: 0x0804 0x04b0

Trojan.Heur.smeirv44zpeby also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.smeirv44zpeby
FireEyeGeneric.mg.7c0e88ec87f181ee
ALYacGen:Trojan.Heur.smeirv44zpeby
CylanceUnsafe
ZillyaBackdoor.Bifrose.Win32.43752
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005376ae1 )
AlibabaBackdoor:Win32/Hupigon.c26d2774
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.c87f18
BitDefenderThetaAI:Packer.96ACF97A1D
VirITBackdoor.Win32.Small.P
CyrenW32/Threat-SysVenFak-based!Maxi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
TrendMicro-HouseCallTROJ_GEN.R002C0RK622
ClamAVWin.Malware.Hupigon-9845802-0
KasperskyVHO:Backdoor.Win32.Hupigon.gen
BitDefenderGen:Trojan.Heur.smeirv44zpeby
NANO-AntivirusTrojan.Win32.Agent.ecbup
CynetMalicious (score: 100)
AvastWin32:GenMalicious-BND [Trj]
Ad-AwareGen:Trojan.Heur.smeirv44zpeby
EmsisoftGen:Trojan.Heur.smeirv44zpeby (B)
ComodoVirus.Win32.Downloader.BA@1cfxaq
DrWebBackDoor.Pigeon1.5760
VIPREGen:Trojan.Heur.smeirv44zpeby
TrendMicroTROJ_GEN.R002C0RK622
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosMal/Generic-S + Mal/Behav-160
APEXMalicious
GDataGen:Trojan.Heur.smeirv44zpeby
JiangminBackdoor/Huigezi.vne
AviraBDS/Hupigon.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASCommon.4C
ArcabitTrojan.Heur.smeirv44zpeby
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Hupigon.C48284
Acronissuspicious
McAfeeArtemis!7C0E88EC87F1
MalwarebytesMalware.AI.990216928
RisingTrojan.Kryptik!1.DF48 (CLASSIC)
YandexTrojan.GenAsa!RANxFZ/MFwo
IkarusBackdoor.Win32.Hupigon
FortinetW32/Hupigon!tr
AVGWin32:GenMalicious-BND [Trj]

How to remove Trojan.Heur.smeirv44zpeby?

Trojan.Heur.smeirv44zpeby removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment