Backdoor

How to remove “Backdoor.Win32.Agent.myubtj”?

Malware Removal

The Backdoor.Win32.Agent.myubtj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.myubtj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Agent.myubtj?


File Info:

crc32: 4FB4CB23
md5: 943b992da5eff312e494f02e270feccf
name: 943B992DA5EFF312E494F02E270FECCF.mlw
sha1: 5078fdbac8b7af3e3b44eb6fb45be6eb447d870a
sha256: 46c3c96de71f691a7247112fe80d61599ab91e8ead7db41cfab9af64357d10cc
sha512: b7dcfc920f9bca227b01a30679936052bfa082625e7ba82883addd896d09411b67a0477e99dc2e8b0838137d8fa9584ae1d6aa183cc8ebfbdbe7ec2f471475e4
ssdeep: 24576:Hq1Zq0nwOIrwC+pu8WM+8wCgil5a6cLH6KVmCcbK1pMVHk5Lka6gtXzd:K1ZqMw2u8m8/Vl5aJj6KVm61pMZSPtX5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: level
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Backdoor.Win32.Agent.myubtj also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057dce51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacMemScan:Trojan.GenericKDZ.75753
CylanceUnsafe
ZillyaDropper.Scrop.Win32.1404
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/Glupteba.9f0ce66b
K7GWTrojan ( 0057dce51 )
Cybereasonmalicious.ac8b7a
CyrenW32/Trojan.IORL-8722
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Filerepmalware-9864117-0
KasperskyBackdoor.Win32.Agent.myubtj
BitDefenderMemScan:Trojan.GenericKDZ.75753
MicroWorld-eScanMemScan:Trojan.GenericKDZ.75753
TencentWin32.Trojan-qqpass.Qqrob.Hrex
Ad-AwareMemScan:Trojan.GenericKDZ.75753
BitDefenderThetaGen:NN.ZexaF.34722.ar3@aqABrDik
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.943b992da5eff312
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
AviraTR/Kryptik.pgdcc
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.30FC47C
MicrosoftTrojan:Win32/Glupteba.QI!MTB
ArcabitTrojan.Generic.D127E9
GDataMemScan:Trojan.GenericKDZ.75753
AhnLab-V3Trojan/Win.Generic.C4493298
McAfeeArtemis!943B992DA5EF
MAXmalware (ai score=87)
MalwarebytesMalware.AI.2177412044
PandaTrj/CI.A
RisingTrojan.Kryptik!1.D63F (CLASSIC)
IkarusTrojan.Win32.Crypt
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Win32.Agent.myubtj?

Backdoor.Win32.Agent.myubtj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment