Spy Trojan

Trojan-Spy.Win32.Mufila.kg removal guide

Malware Removal

The Trojan-Spy.Win32.Mufila.kg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Mufila.kg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Mufila.kg?


File Info:

name: 5CA50C8DBAC2ECBE0B3C.mlw
path: /opt/CAPEv2/storage/binaries/f9a3462171396b9d8b1dcdb301a6681938c54223ad4238a001354454eae38c0c
crc32: 4FBF769E
md5: 5ca50c8dbac2ecbe0b3c744dd554e70c
sha1: 2b43862350cb876bdd48d7c6efcfeb6c25e1ff2a
sha256: f9a3462171396b9d8b1dcdb301a6681938c54223ad4238a001354454eae38c0c
sha512: 0e34eb28c23a4a32bc8a6d6325c1d546cd853d79fac34f6b743d961262ad442c5c45c7ff9dee24347ac4bbcef0b0fc5ae4c0874a5f4b5e75a06d60222aa9529b
ssdeep: 49152:BaBQnOEg9lyX0IcP8Tspu8Zu/jgVvUhEt0/NUE1xAOQSqiiAeUZi:BaBQOLyX0DP8uu80kVc2toNbzttli
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CAA52350CAC0502AE84041BFC1E69B7EDCF85D69039C50D3F3CE989D1AAD9E99F2855F
sha3_384: cffe296e1fe44eac11b2656281671c672f4ed07cc806749018549f647d94955b48e43830801ef290b52750e20d2a9331
ep_bytes: eb080f38200000000000e90020000054
timestamp: 2021-11-09 11:13:31

Version Info:

FileVersion: 8.2.1.7
ProductVersion: 8.2.1.7
FileDescription: Совместимость WIA - TWAIN
CompanyName: Microsoft® C/C++ OpenMP Runtime
LegalCopyright: Copyright (C) 2006-2000 fsgiwPn7EVDV6pC1hbGqtl1yk4fikz95lpha4pqOZZDXOpSMcRmvdBD8T, Inc. All rights reserved.
ProductName:
Comments: ZsA2tBaePU3qhPLmFqIRMnE23vkB4p4gB8XB1FFwcb168wIEQlR1pUtIXnsVwrdrP8XkySfnsYDgyHioRauQwDW
InternalName: dvdupgrd.exe
Translation: 0x0000 0x04b0

Trojan-Spy.Win32.Mufila.kg also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.80003
FireEyeGeneric.mg.5ca50c8dbac2ecbe
CAT-QuickHealTrojanspy.Mufila
ALYacTrojan.GenericKDZ.80003
CylanceUnsafe
ZillyaTrojan.Mufila.Win32.62
K7AntiVirusTrojan ( 005786ed1 )
AlibabaTrojanSpy:Win32/Mufila.1afb626c
K7GWTrojan ( 005786ed1 )
Cybereasonmalicious.350cb8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Packed.Themida.KX
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Mufila.kg
BitDefenderTrojan.GenericKDZ.80003
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Falsesign.Szbx
Ad-AwareTrojan.GenericKDZ.80003
SophosMal/Generic-S
ComodoTrojWare.Win32.UMal.qnpvd@0
DrWebTrojan.PWS.Stealer.31631
TrendMicroTROJ_GEN.R002C0PKM21
McAfee-GW-EditionGenericRXQQ-AK!5CA50C8DBAC2
EmsisoftTrojan.GenericKDZ.80003 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.80003
AviraTR/Spy.Mufila.vvhla
Antiy-AVLTrojan/Generic.ASMalwS.34D5C73
KingsoftWin32.Heur.KVMH008.a.(kcloud)
GridinsoftTrojan.Win32.Packed.vb
MicrosoftTrojan:Win32/Vidar.AA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.AK.C4781812
McAfeeGenericRXQQ-AK!5CA50C8DBAC2
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.MSIL.Reline
MalwarebytesMalware.AI.2919886853
TrendMicro-HouseCallTROJ_GEN.R002C0PKM21
YandexTrojanSpy.Mufila!yVI1l7bcVn4
IkarusTrojan.Win64.Themida
eGambitPE.Heur.InvalidSig
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34062.bM2@aeAX@pbG
AVGWin32:TrojanX-gen [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Spy.Win32.Mufila.kg?

Trojan-Spy.Win32.Mufila.kg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment