Malware

Win32:SuspBehav-E [Heur] removal instruction

Malware Removal

The Win32:SuspBehav-E [Heur] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:SuspBehav-E [Heur] virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:SuspBehav-E [Heur]?


File Info:

name: 9A0BED1C4651CB4081CE.mlw
path: /opt/CAPEv2/storage/binaries/e88829e386cf0c7060cf263b6849f69c2d4803745baff4a61c0e6d74d182ea0a
crc32: 17E6745C
md5: 9a0bed1c4651cb4081ce5761f369411d
sha1: 93f3a135ff7ab91803f517f7f461790e5bcf0548
sha256: e88829e386cf0c7060cf263b6849f69c2d4803745baff4a61c0e6d74d182ea0a
sha512: 45b6152b757b8a0d85e6fe0fbba98bea7393c4b9f974eaf29384d0211446037277943af9f8a5920fdb853b87e9620d3039fe7ec774cc47498ccc3292391cdecc
ssdeep: 49152:qVmWfgoxVtIfCEreczgIPA7U4X7CO80haXX:q8oxVtIfCEreczggYU47LaX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16085C0D39342401AF172603A802E6E6DB4721A3147CFF8B777CD9BEA93276D09629717
sha3_384: a7faf514e144dd1dce1a8fc572b5e3139214affa8e409ac76742d833a943b4518c2bf6814bfee0fe86d8dd8cb1c97962
ep_bytes: 558bec81ecf8030000837d08f07f146a
timestamp: 2010-08-01 10:32:37

Version Info:

0: [No Data]

Win32:SuspBehav-E [Heur] also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Packed
MicroWorld-eScanTrojan.GenericKDZ.87193
FireEyeGeneric.mg.9a0bed1c4651cb40
ALYacTrojan.GenericKDZ.87193
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005916431 )
K7GWTrojan ( 005916431 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.34638.WzW@ayJU9zj
CyrenW32/Kryptik.GMJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPFH
APEXMalicious
ClamAVWin.Packed.Generic-9948303-0
BitDefenderTrojan.GenericKDZ.87193
AvastWin32:SuspBehav-E [Heur]
Ad-AwareTrojan.GenericKDZ.87193
EmsisoftTrojan.GenericKDZ.87193 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.ASProtect
GDataTrojan.GenericKDZ.87193
AviraTR/Crypt.Agent.fqbrt
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!9A0BED1C4651
MAXmalware (ai score=86)
MalwarebytesTrojan.FakeSig
RisingStealer.Agent!8.C2 (TFE:dGZlOgXfXgGoxh0jnw)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HPFH!tr
AVGWin32:SuspBehav-E [Heur]

How to remove Win32:SuspBehav-E [Heur]?

Win32:SuspBehav-E [Heur] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment