Backdoor

About “Backdoor:Win32/Coroxy.G!MTB” infection

Malware Removal

The Backdoor:Win32/Coroxy.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Coroxy.G!MTB virus can do?

  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Coroxy.G!MTB?


File Info:

crc32: 41036564
md5: fca6b8e7be21756ad15b863efe86d4f4
name: FCA6B8E7BE21756AD15B863EFE86D4F4.mlw
sha1: 787885416d0f6a09f7691e9703fa6f9cceba45b3
sha256: 1aef94e54c1af9a8d0c4fa4cbdc602c025a2b10a097e87184ceb89e124d26e6a
sha512: 105b18a82c07bb4d162e507a34a16edda164dedf44b97dba90100927bae4ad48bd6762c220285bc7a25c01620fccbba7cc0eb2992d26aa210bb7bd3320e1152a
ssdeep: 192:C2WjQTbZ1eBppvfj/j2+cPM3P+Q/tCvwSw3uM76V9bhHOkrUNc:C2jTbZ0pj/vcqP+ctCYSw3GV9bhrUN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Coroxy.G!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00578fc91 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.5932
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Scar
ALYacGen:Variant.Doina.8081
CylanceUnsafe
ZillyaTrojan.Coroxy.Win32.88
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Coroxy.e019babf
K7GWTrojan ( 00578fc91 )
Cybereasonmalicious.7be217
CyrenW32/Threat-HLLSI-based!Maximus
SymantecBackdoor.SystemBC
ESET-NOD32a variant of Win32/Coroxy.D
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan.Win32.Scar.tgup
BitDefenderGen:Variant.Doina.8081
NANO-AntivirusTrojan.Win32.Coroxy.ivgrxs
ViRobotTrojan.Win32.Z.Coroxy.13824.A
MicroWorld-eScanGen:Variant.Doina.8081
TencentMalware.Win32.Gencirc.11c3ab59
Ad-AwareGen:Variant.Doina.8081
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.COROXY.SMYXBC3A
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.fca6b8e7be21756a
EmsisoftGen:Variant.Doina.8081 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Multi.qr
AviraHEUR/AGEN.1111611
Antiy-AVLTrojan/Generic.ASMalwS.328A0D9
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Coroxy.G!MTB
GridinsoftTrojan.Win32.Agent.dd!s1
GDataGen:Variant.Doina.8081
TACHYONTrojan/W32.Convagent.13824
AhnLab-V3Malware/Win32.RL_Backdoor.R366856
McAfeeGenericRXAA-FA!FCA6B8E7BE21
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1358454464
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.COROXY.SMYXBC3A
RisingBackdoor.SystemBC!1.D22F (CLASSIC)
YandexTrojan.Coroxy!bg8rBBaYKs0
IkarusTrojan.Win32.Coroxy
MaxSecureTrojan.Malware.82199810.susgen
FortinetW32/Coroxy.D!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Scar.HxQBXE8A

How to remove Backdoor:Win32/Coroxy.G!MTB?

Backdoor:Win32/Coroxy.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment