Trojan

How to remove “Trojan.Heur.VP.dmMfaaElvbpi”?

Malware Removal

The Trojan.Heur.VP.dmMfaaElvbpi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.VP.dmMfaaElvbpi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Heur.VP.dmMfaaElvbpi?


File Info:

name: FE038926560F5AC1ED9A.mlw
path: /opt/CAPEv2/storage/binaries/0464e19d26136c0c820f3d085b4883c251d4d9e80e10ab193fbee0c153a8a166
crc32: A351973E
md5: fe038926560f5ac1ed9ae35ebd821ec7
sha1: 5b6d017f36d1f85afde4a4d7e2dd8a6db612a177
sha256: 0464e19d26136c0c820f3d085b4883c251d4d9e80e10ab193fbee0c153a8a166
sha512: 1b94a19b945a1c0f2badccf9843c1aa7fb51e5f2da5f60c87b94948232ac9a1a48cb10069e3e54dc03db817aec0797d6aa9aba0886a29547b16960622f8bb979
ssdeep: 1536:1Xxao+7ahPUdUVHAIbxC8IS2Ua/DMhpDS+:R+ePUdgH28qYhpS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17943F16E39FD242FF1828837931EC2FA189C346456B973AAD6D1680D56ACA05C433FF4
sha3_384: 8a2e685d1ca1e2ac70a63cc08af6d8d424883620b94104c9320baa49343bddced7c6033e5ee5d23eb0b5a12ca4c26814
ep_bytes: 60be00b040008dbe0060ffff5783cdff
timestamp: 2009-12-04 13:35:59

Version Info:

Translation: 0x0409 0x04b0
Comments: IEFix Utility
FileDescription: Repairs Internet Explorer by registering the core system libraries.
LegalCopyright: © 2006 Ramesh Srinivasan.
ProductName: IEFix
FileVersion: 1.06
ProductVersion: 1.06
InternalName: IEFix
OriginalFilename: IEFix.exe

Trojan.Heur.VP.dmMfaaElvbpi also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.VP.dmMfaaElvbpi
FireEyeGeneric.mg.fe038926560f5ac1
ALYacGen:Trojan.Heur.VP.dmMfaaElvbpi
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
AlibabaTrojanDropper:Win32/Virut.ecd40b64
Cybereasonmalicious.6560f5
BitDefenderThetaAI:Packer.766C1BEC1F
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Mikey-9810063-0
BitDefenderGen:Trojan.Heur.VP.dmMfaaElvbpi
AvastWin32:Patched-AML
Ad-AwareGen:Trojan.Heur.VP.dmMfaaElvbpi
EmsisoftGen:Trojan.Heur.VP.dmMfaaElvbpi (B)
ZillyaTrojan.Scar.Win32.96908
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
SophosGeneric PUA FL (PUA)
IkarusVirus.Win32.Ramnit
GDataGen:Trojan.Heur.VP.dmMfaaElvbpi
JiangminTrojan/Generic.ayffd
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.24F2BC4
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeRDN/Generic.dx
MalwarebytesSality.Virus.FileInfector.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CD322
RisingTrojan.Generic@AI.100 (RDMK:cmRtazpY//4rBFoX3Z5/FOaJGf1A)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.153703990.susgen
FortinetW32/PossibleThreat
AVGWin32:Patched-AML
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Heur.VP.dmMfaaElvbpi?

Trojan.Heur.VP.dmMfaaElvbpi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment