Trojan

Trojan.Heur2.JP.emKfa0R1rYak (file analysis)

Malware Removal

The Trojan.Heur2.JP.emKfa0R1rYak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur2.JP.emKfa0R1rYak virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

buskirava.awardspace.com
bisyeton.netfirms.com
festashka.awardspace.com
bsakurmeh.awardspace.com

How to determine Trojan.Heur2.JP.emKfa0R1rYak?


File Info:

crc32: 8F224242
md5: b7ba7f54e3679dc653b0a7e34ce0e2b0
name: B7BA7F54E3679DC653B0A7E34CE0E2B0.mlw
sha1: 9b5cc57824cecb17be43b35bdf658a952cb67fb4
sha256: d65e3127fdb267c9f2793158bf389f559895d81eaea898ca9853933e1112edff
sha512: 7bf8f53a124eede6a9f8a1d6faf20448ae378769f2b180df8cfc4227c00509eaf275dfe505a07d95eb7123b8c9ae5f875210d26479d119d1403c916cf7e80d0a
ssdeep: 1536:6mUckoLNX/G99ol67COhZ5t+EbDkevpoDFUlM9rdZNOP8p:64LFGDxTcFUK9rdmP8p
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: SVCH0ST.exe
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoftxae Windowsxae Operating System
SpecialBuild:
ProductVersion: 5.1.2600.2180
FileDescription: Generic Host Process for Win32 Services
OriginalFilename: SVCH0ST.exe
Translation: 0x0409 0x04b0

Trojan.Heur2.JP.emKfa0R1rYak also known as:

K7AntiVirusSpyware ( 000340ac1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur2.JP.emKfa0R1rYak
CylanceUnsafe
ZillyaTrojan.Banker.Win32.12004
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWSpyware ( 000340ac1 )
Cybereasonmalicious.4e3679
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Banker.ASW
APEXMalicious
AvastWin32:Banker-FTR [Trj]
KasperskyTrojan-Ransom.Win32.PornoAsset.cupq
BitDefenderGen:Trojan.Heur2.JP.emKfa0R1rYak
SUPERAntiSpywareTrojan.Agent/Gen-Falofn[Cont]
MicroWorld-eScanGen:Trojan.Heur2.JP.emKfa0R1rYak
Ad-AwareGen:Trojan.Heur2.JP.emKfa0R1rYak
SophosTroj/Banker-EOY
ComodoTrojWare.Win32.Spy.Banker.~TH@1839s
BitDefenderThetaAI:Packer.C8CBA64B20
McAfee-GW-EditionBehavesLike.Win32.Fake.lc
FireEyeGeneric.mg.b7ba7f54e3679dc6
EmsisoftGen:Trojan.Heur2.JP.emKfa0R1rYak (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Banker.snn
AviraTR/Crypt.FKM.Gen
eGambitGeneric.PSW
Antiy-AVLTrojan/Generic.ASMalwS.2AE52B8
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Heur2.JP.emKfa0R1rYak
ZoneAlarmTrojan-Ransom.Win32.PornoAsset.cupq
GDataGen:Trojan.Heur2.JP.emKfa0R1rYak
AhnLab-V3Trojan/Win32.Banker.C140014
McAfeeGeneric Malware.mt
MAXmalware (ai score=83)
VBA32BScope.Trojan.Scar
RisingMalware.Heuristic!ET#81% (RDMK:cmRtazo3/+NtKCb64mtWfHexY2TI)
YandexTrojanSpy.Banker.BIPQ
IkarusGeneric.Banker.OT
MaxSecureTrojan.Malware.1195990.susgen
FortinetW32/Banker.BBGH!tr.dldr
AVGWin32:Banker-FTR [Trj]

How to remove Trojan.Heur2.JP.emKfa0R1rYak?

Trojan.Heur2.JP.emKfa0R1rYak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment