Backdoor

How to remove “Backdoor.Win32.Agent.myudhg”?

Malware Removal

The Backdoor.Win32.Agent.myudhg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.myudhg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Agent.myudhg?


File Info:

crc32: CA2ADB9A
md5: 199172dc2093263eed50e3f744859def
name: 199172DC2093263EED50E3F744859DEF.mlw
sha1: c38f07b26060cde49068ee6ca98a58e3cae1b375
sha256: c8ceceea071185485187862365097bbb02345c6519788db06c76d2286bec4efc
sha512: 54526e4aa2f3e2d682653c2e77e5a451ff3d443156a661a7b5de1b37b553054889da6245ed7b08f9076ac0f4139993b4584fb342483cfaa69e018811118095e2
ssdeep: 24576:kijmOmv1ZSO0PgnloOKVEdKlfMeezNEfRmoIXLRn10GEDbsla5I:3qbv1ZRnlA2dKi9h5bwG7MI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: hereon
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Backdoor.Win32.Agent.myudhg also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.36307
ClamAVWin.Packed.Filerepmalware-9864117-0
CAT-QuickHealTrojanpws.Coins
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/Coins.5f2edcae
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastNSIS:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Agent.myudhg
BitDefenderDropped:Trojan.GenericKD.37486338
MicroWorld-eScanDropped:Trojan.GenericKD.37486338
TencentWin32.Trojan-qqpass.Qqrob.Dztx
Ad-AwareDropped:Trojan.GenericKD.37486338
BitDefenderThetaGen:NN.ZexaF.34110.oq0@a8qUccoG
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeDropped:Trojan.GenericKD.37486338
EmsisoftTrojan.Crypt (A)
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_75%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.BSE.HLJWVB
AhnLab-V3Infostealer/Win.CryptBot.R438883
McAfeeArtemis!199172DC2093
MAXmalware (ai score=84)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.BitCoinStealer
PandaTrj/Agent.ALS
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
FortinetW32/multiple_detections
AVGNSIS:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Win32.Agent.myudhg?

Backdoor.Win32.Agent.myudhg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment