Trojan

Trojan.Heur2.ZGY.1 malicious file

Malware Removal

The Trojan.Heur2.ZGY.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur2.ZGY.1 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics

How to determine Trojan.Heur2.ZGY.1?


File Info:

name: C0BA205F153FAC606D20.mlw
path: /opt/CAPEv2/storage/binaries/385b0e94aec47498803a19d8e5fa046cd7d908aa7094abb75f21e03e04dfdc60
crc32: 92E6ABEE
md5: c0ba205f153fac606d203d0787d905c6
sha1: 3295e739562bccd7085509a14a549492c2ea007b
sha256: 385b0e94aec47498803a19d8e5fa046cd7d908aa7094abb75f21e03e04dfdc60
sha512: e8c80e94da9026d7d00eee6c321a5b115df15ab9f90d28703f84b5de7ff74856ddc80ffadc86ea19b63b0b5f216e7f2e937eb80f553563eb2df4743387d7baee
ssdeep: 3072:m98yOPv1FHRJAnld1JXHRaFfZ2b/96HM0XUGXU2Fo21s/xxqrbfAseFqFjob1tE3:DX1FH/evRofYnVDnqr8seU8b1tFNemI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197342359BBAA3F6EFA661BB2467186DF519BF4DCB446837CD2E434BF1C0F14490018A2
sha3_384: 2e7a72e0a336c3cc9457b93d83f8ce95bed9e9a1dd8cd50284e34ba422d41f10f873b9cbb1043cd1c648d64e07953348
ep_bytes: 6801d04300e801000000c3c320c06809
timestamp: 2011-07-24 20:51:11

Version Info:

Translation: 0x0409 0x04b0
CompanyName:
LegalCopyright:
LegalTrademarks:
ProductName:
FileVersion: 88.44.0022
ProductVersion: 88.44.0022
InternalName: DeV-PoinT1e
OriginalFilename: DeV-PoinT1e.exe

Trojan.Heur2.ZGY.1 also known as:

LionicTrojan.Win32.Generic.ljsv
DrWebBackDoor.Bifrost.21105
MicroWorld-eScanGen:Trojan.Heur2.ZGY.1
FireEyeGeneric.mg.c0ba205f153fac60
ALYacGen:Trojan.Heur2.ZGY.1
CylanceUnsafe
VIPREGen:Trojan.Heur2.ZGY.1
SangforTrojan.Win32.CFI.Gen
AlibabaTrojan:Win32/VBKrypt.0fe3f057
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.2227E8F615
CyrenW32/VB.DO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.EYS
APEXMalicious
ClamAVWin.Trojan.Powerspy-6915455-0
KasperskyTrojan.Win32.VBKrypt.wgiw
BitDefenderGen:Trojan.Heur2.ZGY.1
NANO-AntivirusTrojan.Win32.Refroso.gfhgi
AvastFileRepMalware [Trj]
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
Ad-AwareGen:Trojan.Heur2.ZGY.1
EmsisoftGen:Trojan.Heur2.ZGY.1 (B)
ComodoMalware@#z5j6066sao33
ZillyaTrojan.Refroso.Win32.39425
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Heur2.ZGY.1
JiangminTrojan/Generic.ihqq
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.CFI.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.A.Refroso.245629.A
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Malco.R7759
McAfeeArtemis!C0BA205F153F
TACHYONTrojan/W32.Refroso.245629.B
VBA32BScope.Malware-Cryptor.VBCR.2512
MalwarebytesGeneric.Trojan.Dropper.DDS
TencentWin32.Trojan.Vbkrypt.Gdhl
YandexTrojanSpy.Agent!xFj53tNHMks
IkarusTrojan-Dropper.Win32.Bifrose
MaxSecureTrojan.Malware.2566451.susgen
FortinetW32/VBKrypt.BBBQ!tr
AVGFileRepMalware [Trj]
Cybereasonmalicious.f153fa
PandaGeneric Malware

How to remove Trojan.Heur2.ZGY.1?

Trojan.Heur2.ZGY.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment