Backdoor

Backdoor.Win32.Agent.mytyhb removal guide

Malware Removal

The Backdoor.Win32.Agent.mytyhb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.mytyhb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
www.bing.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Backdoor.Win32.Agent.mytyhb?


File Info:

crc32: 00286D5A
md5: a180bdb732597d263105ed421c21d757
name: A180BDB732597D263105ED421C21D757.mlw
sha1: 253574c27703666545f0da23b7277aa5a5b6094c
sha256: ae9df94a3b5e4fd49c3be5b5a8ee7b984de308ba348cd2c007a637cceb551213
sha512: 1c3a7b959d09cfb3a7d47e2ab8cdecc6a0a256ada0197fd1f83592bbf029b41c1da6ad7ce9d9753ec81ed03c24a07790312c3c996f3f2f91256f0115549b85ac
ssdeep: 24576:AyIfojLox0UGvpn302pqa5ugHd+XfyVf5c0E8eoSg1vpADs9:AycMu0U0p302pcgHd+X6Vf5c0awvpv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: HappyNewYear
Comments: This installation was built with Inno Setup.
ProductName: HappyNewYear
ProductVersion: 23.47
FileDescription: HappyNewYear Setup
Translation: 0x0000 0x04b0

Backdoor.Win32.Agent.mytyhb also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35922704
FireEyeTrojan.GenericKD.35922704
ALYacTrojan.GenericKD.35922704
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35922704
K7GWRiskware ( 0040eff71 )
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-9808271-0
KasperskyBackdoor.Win32.Agent.mytyhb
AlibabaTrojan:Win32/Dofoil.5262b265
Ad-AwareTrojan.GenericKD.35922704
EmsisoftTrojan.GenericKD.35922704 (B)
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.fc
SophosMal/Generic-S
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.DA!ml
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D2242310
ZoneAlarmBackdoor.Win32.Agent.mytyhb
GDataTrojan.GenericKD.35922704
CynetMalicious (score: 85)
AhnLab-V3Malware/Gen.Reputation.C4283634
McAfeeArtemis!A180BDB73259
MAXmalware (ai score=83)
MalwarebytesAdware.FileTour
PandaTrj/CI.A
ZonerTrojan.Win32.99098
TrendMicro-HouseCallTROJ_GEN.R002H07LT20
FortinetW32/Agent.MYTXYG!tr.bdr
BitDefenderThetaGen:NN.ZexaF.34700.imGfaKzCVtgc
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.d93

How to remove Backdoor.Win32.Agent.mytyhb?

Backdoor.Win32.Agent.mytyhb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment