Trojan

What is “Trojan.Agent.CUTH”?

Malware Removal

The Trojan.Agent.CUTH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CUTH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.CUTH?


File Info:

crc32: A8290A49
md5: 3a7244a24354068e0e9a2e5061685b6b
name: 3A7244A24354068E0E9A2E5061685B6B.mlw
sha1: 74db5227e9849038da7a968a36500a39a58d81c0
sha256: df0d7ac04ffabbb475bf5ecd147e8aacf8b9fcff1c647125cdc252077405e188
sha512: d6787fc059c1933201b1925b8a8cc219498015fd0f6ca8ecd15cabb5169381990f0454b26c2db964450f877b865bc289bf20ef7fba065126ffe16e48668eff74
ssdeep: 12288:ZSiBFQnG+vrRiIskCR7uCGdeIkAQDedTFO4qaXU4:/MnNrRiIsN8CGoIWDe1FeAU4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 >
InternalName:
FileVersion: 2
License:
CompanyName: <w.gn
LegalTrademarks: GN
ProductName: Flx
ProductVersion: 24a
FileDescription: or
OriginalFilename: fle
Translation: 0x0409 0x04e4

Trojan.Agent.CUTH also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005270b81 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Pigeon1.13646
CynetMalicious (score: 100)
ALYacTrojan.Agent.CUTH
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.49355
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Fareit.ee6b7f85
K7GWTrojan ( 005270b81 )
Cybereasonmalicious.243540
CyrenW32/Trojan.RUTI-7110
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.DVUZ
ZonerTrojan.Win32.66303
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-PSW.Win32.Fareit.dqvj
BitDefenderTrojan.Agent.CUTH
NANO-AntivirusTrojan.Win32.Pigeon1.exzptk
ViRobotTrojan.Win32.Agent.712704.K
MicroWorld-eScanTrojan.Agent.CUTH
TencentMalware.Win32.Gencirc.10b3be37
Ad-AwareTrojan.Agent.CUTH
SophosMal/Generic-S + Mal/Fareit-Q
BitDefenderThetaAI:Packer.936B438711
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_FAREIT.CBQ
McAfee-GW-EditionBehavesLike.Win32.Fareit.jh
FireEyeGeneric.mg.3a7244a24354068e
EmsisoftTrojan.Agent.CUTH (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Fareit.aaho
AviraHEUR/AGEN.1114886
Antiy-AVLTrojan/Generic.ASMalwS.247761B
MicrosoftTrojan:Win32/Fareit!ml
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan-PSW.Win32.Fareit.dqvj
GDataTrojan.Agent.CUTH
AhnLab-V3Suspicious/Win.Delphiless.X2094
Acronissuspicious
McAfeeTrojan-FOTS!3A7244A24354
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Azorult
MalwarebytesTrojan.MalPack
PandaTrj/RnkBend.A
TrendMicro-HouseCallTSPY_FAREIT.CBQ
RisingTrojan.Injector!1.AFE3 (CLASSIC)
YandexTrojan.GenAsa!7/pYOWo15WM
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DXRU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Agent.CUTH?

Trojan.Agent.CUTH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment