Backdoor

Backdoor.Win32.Agent.myucxo removal tips

Malware Removal

The Backdoor.Win32.Agent.myucxo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.myucxo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
NJIEjqRTbnIYnAiJRPvlKPyOPF.NJIEjqRTbnIYnAiJRPvlKPyOPF

How to determine Backdoor.Win32.Agent.myucxo?


File Info:

crc32: F74C48C4
md5: 5da707c4db06e0549e3c2067df1a0256
name: 5DA707C4DB06E0549E3C2067DF1A0256.mlw
sha1: 7ecaecd0be36c45323eb50346f2c2bc8e55783ac
sha256: f02d594d22f31926b6aec336e4b49925a04c14661053fd7fa04726f1ae5334a2
sha512: 344122989146549eb322ae5b4fd0ce95e09a70748ff1a3f5339990373b751cddc82d700ce1132c910b43f0f710941a7b133477df0df42abaa291d0ab4f41070f
ssdeep: 24576:Nu1ZwoyVZqH3krlbp2gexVDAO0e2JSA7+Qz5xrQVthlIvpIlhRRfEj8oakqs2JmZ:Q1ZwPqH32wzDF0TYA7+MLryspch+lNnZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: plag
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Backdoor.Win32.Agent.myucxo also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Filerepmalware-9864117-0
McAfeeArtemis!5DA707C4DB06
ZillyaTrojan.Coins.Win32.6659
SangforTrojan.Win32.Save.a
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastNSIS:CrypterX-gen [Trj]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Agent.myucxo
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34058.oq0@aGvbS0gG
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.5da707c4db06e054
EmsisoftTrojan.Crypt (A)
AviraHEUR/AGEN.1140896
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmHEUR:Trojan-PSW.Win32.Coins.gen
GDataWin32.Trojan.BSE.HLJWVB
AhnLab-V3Malware/Win.Generic.C4589523
VBA32BScope.Trojan.Azorult
MalwarebytesMalware.AI.1294164741
RisingTrojan.Kryptik!1.B40D (CLASSIC)
IkarusMalware.Win32.AVEvader
AVGNSIS:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM42.0.3F5B.Malware.Gen

How to remove Backdoor.Win32.Agent.myucxo?

Backdoor.Win32.Agent.myucxo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment