Spy Trojan

Trojan-Spy.MSIL.Xegumumune removal guide

Malware Removal

The Trojan-Spy.MSIL.Xegumumune is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.MSIL.Xegumumune virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan-Spy.MSIL.Xegumumune?


File Info:

crc32: 14195E61
md5: 111dc5a93286a5a6f139d31dcc78cc66
name: payroll.exe
sha1: e29a891f02c9335cf7a62f8c3d21e8997a71baa7
sha256: 0f031d7e8aec33646616d6491275faf35fb8eb7ec300a728c2caa664a5a98317
sha512: 44c3fe470e62db07836d2d0f8f935923e1c2b5c4303634d10d3dd17b04164151b08c64e07d879c0b506c366fca58578debe0ef5cf6ad6b4a1e0e8779f93849d1
ssdeep: 6144:evNiYhnq+p7myZmRJilUmlj3RZ3+sKs7KdfVsU8ayUeHGPD:whnq0mElP33+CKOUv7PD
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Trojan-Spy.MSIL.Xegumumune also known as:

MicroWorld-eScanTrojan.GenericKD.42894661
Qihoo-360HEUR/QVM03.0.2AB5.Malware.Gen
McAfeeArtemis!111DC5A93286
CylanceUnsafe
AegisLabTrojan.MSIL.Xegumumune.l!c
K7AntiVirusTrojan ( 005585561 )
BitDefenderTrojan.GenericKD.42894661
K7GWTrojan ( 005585561 )
Cybereasonmalicious.f02c93
CyrenW32/MSIL_Agent.CC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.SXL
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Xegumumune.gen
AlibabaTrojan:Win32/runner.ali1000123
TencentWin32.Trojan.Inject.Auto
EmsisoftTrojan.GenericKD.42894661 (B)
ComodoMalware@#2ryd8jz4pt81u
F-SecureTrojan.TR/Kryptik.zocsm
DrWebTrojan.DownLoader33.22148
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FortinetMSIL/Kryptik.SXL!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.111dc5a93286a5a6
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
F-ProtW32/MSIL_Agent.CC.gen!Eldorado
AviraTR/Kryptik.zocsm
MAXmalware (ai score=85)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan-Spy.MSIL.Xegumumune.gen
MalwarebytesTrojan.MSCrypt.MSIL.Generic
RisingBackdoor.Netwire!8.10EAF (CLOUD)
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
GDataWin32.Backdoor.NetWireRC.TVMAFH
BitDefenderThetaGen:NN.ZemsilF.34104.wm0@aWCgs7n
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Spy.MSIL.Xegumumune?

Trojan-Spy.MSIL.Xegumumune removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment