Trojan

About “Trojan.Hide.Heur” infection

Malware Removal

The Trojan.Hide.Heur is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Hide.Heur virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Hide.Heur?


File Info:

crc32: A69DF649
md5: 735745a952473faf5306551a24c95050
name: 735745A952473FAF5306551A24C95050.mlw
sha1: 33033eafc110a7fbff26be5b12e756564eca032b
sha256: b9856de14002bafec77dd5337e2de2cc95ce795edc2a4a0a00f055d438f3abd8
sha512: 8ed8ffda2398498c80b012c4dceddf47240cb1de43404eebe4545ce625198f549f6cec114fc9d0a515733700ab9bed3b00cba2fa19a719515c50b7741bc8dd5f
ssdeep: 12288:6vuX/f3+Fso9uLSTG7B9+TdVUOzUUOyCE1T9W:TX3+9mqG7L+xV99h31k
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

Info: x414x430x43dx43dx44bx439 x43fx430x43ax435x442 x431x44bx43b x441x43ex437x434x430x43d x441 x43fx43ex43cx43ex449x44cx44e SFX Creator
LegalCopyright: DSGame
FileVersion: 1.0.0.0
CompanyName: DSGame
ProductName: CleanZ
FileDescription: Clean your PC
Translation: 0x0419 0x04e3

Trojan.Hide.Heur also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.40419019
ALYacTrojan.GenericKD.40419019
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053bb151 )
BitDefenderTrojan.GenericKD.40419019
K7GWTrojan ( 0053bb151 )
Cybereasonmalicious.952473
ArcabitTrojan.Generic.D268BECB
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Diztakun.21510338
NANO-AntivirusTrojan.Win32.LockScreen.fgypyb
TencentWin32.Trojan.Generic.Afrj
Ad-AwareTrojan.GenericKD.40419019
SophosMal/Generic-S
ComodoMalware@#1stmsqbo8ffbv
F-SecureTrojan.TR/Ransom.avizb
DrWebTrojan.MulDrop9.2723
McAfee-GW-EditionBehavesLike.Win32.Ransom.gc
FireEyeTrojan.GenericKD.40419019
EmsisoftTrojan.GenericKD.40419019 (B)
JiangminTrojan.Generic.arosj
AviraTR/Ransom.avizb
MAXmalware (ai score=99)
Antiy-AVLTrojan[RemoteAdmin]/Win32.NetCat
MicrosoftTrojan:Win32/Vigorf.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.40419019
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C2705677
McAfeeArtemis!735745A95247
VBA32Trojan.Hide.Heur
MalwarebytesTrojan.Script
PandaTrj/CI.A
ESET-NOD32multiple detections
RisingTrojan.Azden!8.F0E3 (CLOUD)
YandexTrojan.Agent!3ZGVKC89R+4
IkarusTrojan.Win32.LockScreen
FortinetW32/Generic!tr
BitDefenderThetaGen:NN.ZelphiF.34590.dG0@amN5nNei
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.243

How to remove Trojan.Hide.Heur?

Trojan.Hide.Heur removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment