Trojan

TrojanDownloader.Hicrazyk removal

Malware Removal

The TrojanDownloader.Hicrazyk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader.Hicrazyk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

stat.fjmjm.com
www.fjmjm.com

How to determine TrojanDownloader.Hicrazyk?


File Info:

crc32: F08DDE5A
md5: e0495d2b7f9f909ac10b70167d0f625f
name: E0495D2B7F9F909AC10B70167D0F625F.mlw
sha1: 846861c32c4464d27f1818c34d031fdb735df4a2
sha256: 24977a66909a1e1ab490768f5ff9b4132891e10be5d72d1ddeb1b9907789685d
sha512: f40361fb15cee714cb575a1cfd7bb11b913785f54f7d46bd763428e9d01ef4c7f677fcebdc0382fb811df3854db8d7aca371d84c65d45d2b4fcabaabe4324bf8
ssdeep: 24576:1o4hsQf7Q74eLEhQKu1i5NLqDYXyvDB2NeJfGaJYk1UsRN6R:FsQzQseL0QKlNuN7seJ+2Yk/uR
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Corporation. All rights reserved.
FileVersion: 1.1.0.0
CompanyName: MeinV
Comments: http://www.sd.com
ProductName: x95eax7535x6d4fx89c8x5668
ProductVersion: 1.1.0.0
FileDescription: Installer Application
Translation: 0x0000 0x03a8

TrojanDownloader.Hicrazyk also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 0049a2d31 )
DrWebTrojan.StartPage.64356
CynetMalicious (score: 99)
ALYacDropped:Trojan.GenericKD.1706384
CylanceUnsafe
SangforSuspicious.Win32.Malware.gen
K7GWTrojan-Downloader ( 0049a2d31 )
Cybereasonmalicious.b7f9f9
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Downloader.Agent.NAQ potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Msposer-7564610-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderDropped:Trojan.GenericKD.1706384
NANO-AntivirusTrojan.Win32.StartPage.dbbpep
MicroWorld-eScanDropped:Trojan.GenericKD.1706384
TencentWin32.Trojan.Generic.Aguj
Ad-AwareDropped:Trojan.GenericKD.1706384
SophosGeneric ML PUA (PUA)
ComodoMalware@#3630z4vy6ty56
BitDefenderThetaAI:Packer.8B5FDEED1D
VIPREShandian (fs)
McAfee-GW-EditionBehavesLike.Win32.Vilsel.tc
FireEyeDropped:Trojan.GenericKD.1706384
EmsisoftDropped:Trojan.GenericKD.1706384 (B)
JiangminTrojan-Downloader.Win32.Hicrazyk.a
AviraHEUR/AGEN.1129105
Antiy-AVLTrojan/Generic.ASMalwNS.AD7
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1A0990
GDataDropped:Trojan.GenericKD.1706384
McAfeeArtemis!E0495D2B7F9F
MAXmalware (ai score=100)
VBA32TrojanDownloader.Hicrazyk
MalwarebytesMalware.AI.1412075712
PandaTrj/CI.A
YandexRiskware.Agent!9RO9lJIOnZU
IkarusTrojan.Win32.Agent
FortinetW32/StartPage.NY!tr
AVGWin32:Malware-gen

How to remove TrojanDownloader.Hicrazyk?

TrojanDownloader.Hicrazyk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment