Trojan

Trojan.Heur.xmKfrrTJm9niD (file analysis)

Malware Removal

The Trojan.Heur.xmKfrrTJm9niD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.xmKfrrTJm9niD virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Heur.xmKfrrTJm9niD?


File Info:

name: 69CC95942A8BFB3C0FB2.mlw
path: /opt/CAPEv2/storage/binaries/dd9c69aedb6f3dcde518ca9f72c60614645d7418b3d0540074c44f8c49d85133
crc32: 7F5B0EAC
md5: 69cc95942a8bfb3c0fb27d59978068a3
sha1: 81401811028b7fb79b1b5301927c01fbaf2dfd6b
sha256: dd9c69aedb6f3dcde518ca9f72c60614645d7418b3d0540074c44f8c49d85133
sha512: 9717678a88d99c5173cf5a4b8ece72b09c0c597ff0bec7ee5eecc9988ac756d5854e9cd28983e72a67d2da30a68d33acd84c308f8fa6c724ddb70a8b41beddaa
ssdeep: 6144:MVOfZTZiOydo+h9g1V5M4orn+GrtY36V7w5KjM9AC9LzfMwHeOQoFRROX7O86fZe:qozGdX0M4ornOmZIzfMwHHQmRROXK86c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1808412B1F090A096D8E724F948398C712557BC7EC4F09A0951DEBB20EEB3706A65BD1F
sha3_384: 8bdabfdbeed4c73d7d20daca7e4e7520a6e398b8890758b998ec038d6b937092769e1953f5392ebd1fc2c0e9e9a66adf
ep_bytes: 60be00a048008dbe0070f7ff57eb0b90
timestamp: 2018-10-16 22:28:49

Version Info:

FileVersion: 8.0.182.0
Comments: Java Runtime
FileDescription: Java Runtime Environment 8.0 Update 192 Katılımsız
ProductVersion: 3.3.14.2
LegalCopyright: © 2018 NouS
CompanyName: Hazırlayan ::.NouS.::
Translation: 0x0809 0x04b0

Trojan.Heur.xmKfrrTJm9niD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur.xmKfrrTJm9niD
FireEyeGen:Trojan.Heur.xmKfrrTJm9niD
SkyhighBehavesLike.Win32.TrojanAitInject.fc
McAfeeArtemis!69CC95942A8B
MalwarebytesMalware.AI.1222938242
SangforTrojan.Win32.Agent.Vhak
ArcabitTrojan.Heur.xmKfrrTJm9niD
APEXMalicious
BitDefenderGen:Trojan.Heur.xmKfrrTJm9niD
EmsisoftGen:Trojan.Heur.xmKfrrTJm9niD (B)
VIPREGen:Trojan.Heur.xmKfrrTJm9niD
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
MAXmalware (ai score=85)
XcitiumMalware@#2c2jxdqohhkfw
GDataGen:Trojan.Heur.xmKfrrTJm9niD
BitDefenderThetaAI:Packer.E945B1351D
ALYacGen:Trojan.Heur.xmKfrrTJm9niD
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09JT22
MaxSecureTrojan.Malware.73921215.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Trojan.Heur.xmKfrrTJm9niD?

Trojan.Heur.xmKfrrTJm9niD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment