Malware

Win32/Cimag.HR (file analysis)

Malware Removal

The Win32/Cimag.HR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Cimag.HR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Cimag.HR?


File Info:

name: 951C68E6F1DFDEE39ED6.mlw
path: /opt/CAPEv2/storage/binaries/f34d154573f119c9adbf6c6eda20f3cb01a985f3f47a9e2eae85e4d60791b881
crc32: 69185181
md5: 951c68e6f1dfdee39ed6e799e250d12e
sha1: 6b6c309720bce87434d36fe1e550e292f6aef62f
sha256: f34d154573f119c9adbf6c6eda20f3cb01a985f3f47a9e2eae85e4d60791b881
sha512: 97d4957249599b273e1881fd672c25ba0c50e4af7400384d7fd49523eaa3959b42b999b9045d2951203e92f5c5bd7bfc783d5f57d20b872af3f8da2c502595c7
ssdeep: 3072:gSafVNwNz8jab1e7QEatc3TmOlRsgxJPY/33/6ZVcS:gScjs12QEVTQg7Y/33ic
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T163C3F183324814D7F6EB0C7DA2CE71B7026CB96A01DDD02367E8CC999DE97958B56B03
sha3_384: d0487aaa268b67ea44f59afd59d8e49db601ff320a983d2b6ed8ce78cf0bca6f6ac67de038854ea66a6d9d465ae0893e
ep_bytes: 6a706835530110e854720000893d0753
timestamp: 2010-06-09 20:53:54

Version Info:

ActiveMovie: Filter dll
Comments: CyberLink Video/SP Filter
CompanyName: CyberLink Corp.
FileDescription: CyberLink Video/SP Filter
FileVersion: 8.4.1408
InternalName: CLVSD.AX
LegalCopyright: Copyright (c) CyberLink Corp. 1997-2002
LegalTrademarks: CyberLink Corp.
OLESelfRegister: AM20
OriginalFilename: CLVSD.AX
PrivateBuild: 1
ProductName: CyberLink PowerDVD
ProductVersion: 8.4.1408
SpecialBuild:
Translation: 0x0409 0x04e4

Win32/Cimag.HR also known as:

LionicTrojan.Win32.Mufanom.lnbR
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Hiloti.2
FireEyeGeneric.mg.951c68e6f1dfdee3
CAT-QuickHealTrojan.Hiloti.gen
SkyhighBehavesLike.Win32.Dropper.ch
McAfeeHiloti.gen.z
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.94041
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Cimag.01d592fe
K7GWTrojan ( 0028568f1 )
K7AntiVirusTrojan ( 0028568f1 )
BitDefenderThetaGen:NN.ZedlaF.36802.hq8@a06xmjob
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Cimag.HR
APEXMalicious
ClamAVWin.Trojan.Hiloti-7946
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Hiloti.2
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Cryptor-A04
EmsisoftGen:Variant.Hiloti.2 (B)
F-SecureTrojan.TR/Hiloti.D.126976
DrWebTrojan.Hiloti.based.2
VIPREGen:Variant.Hiloti.2
TrendMicroTROJ_HILOTI.SMEA
Trapminesuspicious.low.ml.score
SophosMal/Hiloti-D
SentinelOneStatic AI – Malicious PE
WebrootTrojan.W32.Hiloti.Gen
GoogleDetected
AviraTR/Hiloti.D.126976
VaristW32/Hiloti.R.gen!Eldorado
Antiy-AVLTrojan/Win32.Cimag
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Hiloti.gen!D
XcitiumMalware@#31lllmry42qop
ArcabitTrojan.Hiloti.2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Hiloti.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hiloti6.Gen
VBA32BScope.Malware-Cryptor.Tip
ALYacGen:Variant.Hiloti.2
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_HILOTI.SMEA
RisingTrojan.Hiloti!8.74D (TFE:2:DI1asnfTjtT)
YandexTrojan.GenAsa!E64dUR2YmSs
IkarusVirus.Win32.Cryptor
FortinetW32/PackedHiloti.Z!tr
AVGWin32:Cryptor-A04
DeepInstinctMALICIOUS

How to remove Win32/Cimag.HR?

Win32/Cimag.HR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment