Trojan

Trojan.Agent.FYMA information

Malware Removal

The Trojan.Agent.FYMA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FYMA virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan.Agent.FYMA?


File Info:

name: FD5B8C9807902BC31399.mlw
path: /opt/CAPEv2/storage/binaries/482257b78e2c4a2c32b6f6300cf80e0762903f171fa5c6ac3c24f2e23621acbd
crc32: 6EA26FAD
md5: fd5b8c9807902bc313996578aa2f497a
sha1: 5f89d16fd3e20983066e4fd74922dc1ac6cfc9c8
sha256: 482257b78e2c4a2c32b6f6300cf80e0762903f171fa5c6ac3c24f2e23621acbd
sha512: 7a665ba44c553b958b548f2872cc93d4928a1f57d7c306b031c76d01610b399bc503356a5b0482ea1c943572237873853b1e4c46c37224addf01869e6e611395
ssdeep: 3072:rPpb0iZGjXpoGoByXPQs2UTXQ8yb7aFcHiSIvF68fJR:rPpb0iZGbpYByPT7lyvIcCSIvF68f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137D39E913277893DC9111675053B6AADA030AFCA3E7283972766B2EF7D7321268D0FD1
sha3_384: 22b77786abd84133b18e896f4deacd7ce82233de8a5b5b429b88de3a2d250dcd94bbf29625b82f06002be6a1e13036cc
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-15 19:01:50

Version Info:

Translation: 0x0000 0x04b0
Comments: Notepad++ : a free (GNU) source code editor
CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
FileVersion: 8.2.1.0
InternalName: Ulhfyubsl.exe
LegalCopyright: Copyleft 1998-2017 by Don HO
LegalTrademarks:
OriginalFilename: Ulhfyubsl.exe
ProductName: Notepad++
ProductVersion: 8.2.1.0
Assembly Version: 8.2.1.0

Trojan.Agent.FYMA also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Multi.GenericML.4!c
MicroWorld-eScanTrojan.Agent.FYMA
FireEyeTrojan.Agent.FYMA
McAfeeRDN/Real Protect-LS
MalwarebytesTrojan.MalPack.GS
AlibabaTrojan:MSIL/DropperX.0815f15c
K7GWTrojan-Downloader ( 0059476a1 )
BitDefenderThetaGen:NN.ZemsilF.34786.im0@aapui2
CyrenW32/MSIL_Agent.DKY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.MFF
TrendMicro-HouseCallTROJ_GEN.R002C0PG522
Paloaltogeneric.ml
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderTrojan.Agent.FYMA
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Agent.Efax
SophosMal/Generic-S + Troj/Krypt-LV
TrendMicroTROJ_GEN.R002C0PG522
McAfee-GW-EditionRDN/Real Protect-LS
EmsisoftTrojan.Agent.FYMA (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.Agent.XO2M5F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R484432
MAXmalware (ai score=87)
APEXMalicious
RisingTrojan.Generic/MSIL@AI.94 (RDM.MSIL:bW9Al98b3P8ON85iNngiBw)
FortinetMSIL/Agent.MEL!tr.dldr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.FYMA?

Trojan.Agent.FYMA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment