Backdoor

Backdoor.Win32.Agent.myufhk removal guide

Malware Removal

The Backdoor.Win32.Agent.myufhk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.myufhk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Detects the presence of Windows Defender AV emulator via files
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Agent.myufhk?


File Info:

name: 09A2D41CAB09B8BF5AF4.mlw
path: /opt/CAPEv2/storage/binaries/14e21bb275be354c68f0d0a176b2fe589b2af6e9cea81aeb7fd7fdc87dfcc6ef
crc32: 6F026C94
md5: 09a2d41cab09b8bf5af446871b8d8f9f
sha1: 09514c3300c0a8da440099ad6ecce39cd449e1dc
sha256: 14e21bb275be354c68f0d0a176b2fe589b2af6e9cea81aeb7fd7fdc87dfcc6ef
sha512: 8a0387e78e193fe4f20553462d61eb2236e63f81c5749262e8373a24fbc8dd7d2ec769e67678c4323f7856fcc2911abadc87b30d22992ddb6b38e4cafed98d19
ssdeep: 98304:S1EyttttttttXtttttttt6x7WKpOEYMP8TTjPnPCDexiO75F1Nv6563T:S1E3x7WFoEWNO1NxD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A2633A0BDB28C76E5162173445926F0D731CFA197080ED7DB28BD0A3B39ED29E671E4
sha3_384: 8f798eb9ee407943132e33ded0e3cfc63354669b9b0522c4d61b65e9cc8aac504bcdd2f3deb4505a9805333b70a7b8a2
ep_bytes: 558bec6aff6878c84100684095410064
timestamp: 2016-04-02 22:14:00

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.7.0.3900
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2016 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: April 1, 2016
ProductName: 7-Zip SFX
ProductVersion: 1.7.0.3900
Translation: 0x0000 0x04b0

Backdoor.Win32.Agent.myufhk also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.m!c
MicroWorld-eScanTrojan.GenericKD.46551375
ALYacVB:Trojan.Valyria.4308
CylanceUnsafe
BitDefenderTrojan.GenericKD.46551375
ArcabitTrojan.Generic.D2C6514F
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9874371-0
KasperskyBackdoor.Win32.Agent.myufhk
RisingTrojan.HiddenRun/SFX!1.D52F (CLASSIC)
EmsisoftTrojan.GenericKD.46551375 (B)
FireEyeTrojan.GenericKD.46551375
SophosTroj/Agent-BGQN
AviraTR/Agent.pxmjv
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataVB:Trojan.Valyria.4308
CynetMalicious (score: 100)
McAfeeArtemis!09A2D41CAB09
MAXmalware (ai score=87)
MalwarebytesTrojan.Dropper.Generic
TencentTrojan.Win32.BitCoinMiner.la
IkarusTrojan-Spy.RedLineStealer
FortinetW32/Agent.ACXU!tr
AVGScript:SNH-gen [Trj]
AvastScript:SNH-gen [Trj]

How to remove Backdoor.Win32.Agent.myufhk?

Backdoor.Win32.Agent.myufhk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment