Backdoor

Backdoor.Win32.Agent.mytpfh removal tips

Malware Removal

The Backdoor.Win32.Agent.mytpfh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.mytpfh virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.

Related domains:

list.58guyu.com
down01.58guyu.com
cdn.vy68.com
d.sosocv.com
apps.game.qq.com
brickola.cn
js.shuinile.cn

How to determine Backdoor.Win32.Agent.mytpfh?


File Info:

crc32: 4DAFDD72
md5: 31f8836c7a010e89efdb86d44c4ceb97
name: 31f8836c7a010e89efdb86d44c4ceb97.exe
sha1: 041e0fe5da7a3606e9ad4d08ab6fc99a016f64e9
sha256: dedc164f3bd9f4cd27d5e6120fd2009466e5256d309c1b7729c4b21a95c9813c
sha512: fde772e5dfb225b404c7f9929d157324147a782d871c61dd3b88b26da5e8e2e46a57fecfcecc5b9463061afa00a4738b5007e8c17eb9c0f98f5acf1d78f42d08
ssdeep: 24576:oAf/fP20kXjj/L6bhgCswWnEfogF4ECl46Qig/L2lLYxMxrYgrkzLWqq12:bXCf/Lqdsw9QgYlbQ+sZgrg5q12
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Agent.mytpfh also known as:

MicroWorld-eScanDropped:Trojan.GenericKD.42070735
FireEyeGeneric.mg.31f8836c7a010e89
Qihoo-360HEUR/QVM14.0.7901.Malware.Gen
McAfeeArtemis!31F8836C7A01
AegisLabTrojan.Win32.Agent.m!c
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderDropped:Trojan.GenericKD.42070735
K7GWTrojan ( 005329b91 )
K7AntiVirusTrojan ( 005329b91 )
TrendMicroCryp_Xed-12
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
GDataDropped:Trojan.GenericKD.42070735
KasperskyBackdoor.Win32.Agent.mytpfh
AlibabaTrojanDropper:Win32/dropper.ali1003001
NANO-AntivirusTrojan.Win32.Inject3.gfgvik
TencentWin32.Backdoor.Agent.Lkxs
Ad-AwareDropped:Trojan.GenericKD.42070735
SophosMal/EncPk-BW
ComodoPacked.Win32.Klone.~KMG@1knj1d
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.Inject3.17918
VIPREPacked.Win32.Upack (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
Trapminemalicious.high.ml.score
EmsisoftDropped:Trojan.GenericKD.42070735 (B)
IkarusTrojan-PSW.OnlineGames
JiangminTrojan.Generic.dzgpr
AviraTR/Downloader.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D281F2CF
ZoneAlarmBackdoor.Win32.Agent.mytpfh
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Packed/Upack
Acronissuspicious
BitDefenderThetaAI:Packer.D8BFB2CF24
ALYacDropped:Trojan.GenericKD.42070735
MAXmalware (ai score=88)
VBA32Malware-Cryptor.Inject.gen
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/PSW.OnLineGames.QZO
TrendMicro-HouseCallCryp_Xed-12
RisingStealer.OnLineGames!8.131 (CLOUD)
YandexBackdoor.Agent!HC2a7ib+Z/s
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Onlinegames.QZO!tr
AVGFileRepMalware
Cybereasonmalicious.c7a010
Paloaltogeneric.ml
MaxSecureTrojan.Malware.74671011.susgen

How to remove Backdoor.Win32.Agent.mytpfh?

Backdoor.Win32.Agent.mytpfh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment