Trojan

Trojan.Heur2.VP2.ei0aaGbberii (file analysis)

Malware Removal

The Trojan.Heur2.VP2.ei0aaGbberii is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur2.VP2.ei0aaGbberii virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Heur2.VP2.ei0aaGbberii?


File Info:

crc32: E4579B6A
md5: 6c5ceff39587f2ce6a16a989a68d18ee
name: 6C5CEFF39587F2CE6A16A989A68D18EE.mlw
sha1: d08c0abc37e32fc3b580b065acd4a6a72302c709
sha256: 6b2211f46bff00b3ec48351b8cc186ea8b32b2a868a391e588a457c6e7882f9f
sha512: 84b46141620892acdef31c8904559c41c2be7e02bf454163579a9ba3806264aa4cc704f333a18a2f9db56a50b2ada5aad8281dc62528d4c850b8d6481eaf997c
ssdeep: 1536:eu7xcjIrrWb0EvobHXt+VXHX6XdWOj8sFGM290pxYc:eu7xcjAWbq9+VXKgOj8sFGMuPc
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: hd9h219ch19f1c9h19c
FileVersion: 1.00
OriginalFilename: hd9h219ch19f1c9h19c.exe
ProductName: hd9h219ch19f1c9h19c

Trojan.Heur2.VP2.ei0aaGbberii also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Poison.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.Cybergate.1
ClamAVWin.Trojan.Agent-828832
ALYacGen:Trojan.Heur2.VP2.ei0aaGbberii
CylanceUnsafe
ZillyaBackdoor.Poison.Win32.45259
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaBackdoor:Win32/Sdbot.225a7d57
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EWB
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Poison.chxo
BitDefenderGen:Trojan.Heur2.VP2.ei0aaGbberii
NANO-AntivirusTrojan.Win32.Poison.iovea
ViRobotTrojan.Win32.A.PSW-Rebnip.344576
MicroWorld-eScanGen:Trojan.Heur2.VP2.ei0aaGbberii
TencentWin32.Backdoor.Poison.bpay
Ad-AwareGen:Trojan.Heur2.VP2.ei0aaGbberii
SophosMal/Generic-G
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
F-SecureTrojan.TR/Crypt.PEPM.Gen
BitDefenderThetaAI:Packer.AB57663321
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.6c5ceff39587f2ce
EmsisoftGen:Trojan.Heur2.VP2.ei0aaGbberii (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Poison.mvi
WebrootW32.Trojan.Gen
AviraTR/Crypt.PEPM.Gen
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.3434DF
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Heur2.VP2.ei0aaGbberii
GDataGen:Trojan.Heur2.VP2.ei0aaGbberii
TACHYONBackdoor/W32.Bifrose.67072.L
AhnLab-V3Trojan/Win32.Gen
McAfeeArtemis!6C5CEFF39587
MAXmalware (ai score=100)
VBA32BScope.Trojan.VBKrypt
PandaTrj/CI.A
YandexBackdoor.Poison!DZGjyZqgGBE
IkarusVirus.Win32.VBInject
FortinetW32/Magania.IDPJ!tr
AVGWin32:Malware-gen

How to remove Trojan.Heur2.VP2.ei0aaGbberii?

Trojan.Heur2.VP2.ei0aaGbberii removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment