Trojan

What is “Trojan.Heur.XmKfXGRAqnmc”?

Malware Removal

The Trojan.Heur.XmKfXGRAqnmc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.XmKfXGRAqnmc virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Exhibits behavior characteristic of Troldesh ransomware

How to determine Trojan.Heur.XmKfXGRAqnmc?


File Info:

crc32: 1A4EFFC0
md5: 08b26443b97a20952e0279fe2163ae2e
name: 08B26443B97A20952E0279FE2163AE2E.mlw
sha1: 6efbc1098219e74a895031d3819a958a50d337e5
sha256: de41aa97e54c78f8d87f8d93064895a68e5e802037c238250a58d510965483cb
sha512: 8376e4e596c9beded9f3f19ec3a7f40924a05ec63662b3eadd261586c679d016f56f55989af7f3e3d0209e33b2d913d6a67b22f5fef25eb126ef2ddc515deb3b
ssdeep: 24576:usAlIp3m2QqVWGVdGcZ5G3mclq7tXmAL/frV3b7na4J4b:uxla2BUWyvw3mclkt2+/T1XnaWg
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: CSRSS.Exe
FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.3.9600.16384
FileDescription: Client Server Runtime Process
OriginalFilename: CSRSS.Exe
Translation: 0x0409 0x04b0

Trojan.Heur.XmKfXGRAqnmc also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b39e91 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4932
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Shade
CylanceUnsafe
ZillyaTrojan.Generic.Win32.380043
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Troldesh.08218fc1
K7GWTrojan ( 004b39e91 )
Cybereasonmalicious.3b97a2
BaiduWin32.Trojan.FileCoder.b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Shade.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.XmKfXGRAqnmc
NANO-AntivirusTrojan.Win32.Encoder.fkrgmo
MicroWorld-eScanGen:Trojan.Heur.XmKfXGRAqnmc
TencentWin32.Trojan.Filecoder.Hfe
Ad-AwareGen:Trojan.Heur.XmKfXGRAqnmc
SophosMal/Generic-R + Mal/Troldesh-A
ComodoMalware@#2886lyojn837v
BitDefenderThetaAI:Packer.B58597121C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fake.bc
FireEyeGeneric.mg.08b26443b97a2095
EmsisoftGen:Trojan.Heur.XmKfXGRAqnmc (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.FKM.Gen
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Heur.XmKfXGRAqnmc
GDataGen:Trojan.Heur.XmKfXGRAqnmc
AhnLab-V3Trojan/Win32.FakeMS.R134559
McAfeeArtemis!08B26443B97A
MAXmalware (ai score=100)
VBA32Trojan.Encoder
MalwarebytesTrojan.FakeMS
PandaTrj/GdSda.A
IkarusTrojan-Ransom.Troldesh
FortinetW32/Troldesh.71B6!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Heur.XmKfXGRAqnmc?

Trojan.Heur.XmKfXGRAqnmc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment