Spy Trojan

What is “Trojan-Spy.Win32.Xegumumune.dbj”?

Malware Removal

The Trojan-Spy.Win32.Xegumumune.dbj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Xegumumune.dbj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Spy.Win32.Xegumumune.dbj?


File Info:

crc32: B15C9968
md5: 2820f8605681c7e439d890edb4e895be
name: ndfghjkxcvcvbn.exe
sha1: a4e76b9610b2a2db1215479e2b5ddfbfdc735ce0
sha256: ea88878cfc8d1ef15471adf2c8ec7cf5ca78b6cc9c8b1bd4e93c40503773b9da
sha512: f87e3b7f8c5a1d5b0221218fa628727696c572c72495ef73e964f56592f68f8732e0c0bf3c35954859e6ddac51d3c9557036c14f07d1eda796e1a3cdd6509b9c
ssdeep: 768:waVUlz9DUAe1/gjVMtVj9kQ9+U3OVbWdFJSE+5joLaVUlz9DUAe1/gjVMtVj9kQ:wu/gi/+DWHJLLu/gi/+D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x03fc 0x04b0
InternalName: orbito
FileVersion: 1.00
CompanyName: macrocos
ProductName: uncentur
ProductVersion: 1.00
OriginalFilename: orbito.exe

Trojan-Spy.Win32.Xegumumune.dbj also known as:

McAfeeFareit-FQZ!2820F8605681
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.42253091
K7GWTrojan ( 0055eda91 )
K7AntiVirusTrojan ( 0055eda91 )
Invinceaheuristic
CyrenW32/VBInject.ACI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EJYJ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Xegumumune.dbj
AlibabaTrojan:Win32/Injector.08d6fbb1
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.42253091
EmsisoftTrojan.GenericKD.42253091 (B)
ComodoMalware@#3ansd385j2hum
DrWebTrojan.DownLoader32.48786
TrendMicroTrojan.Win32.WACATAC.THAAFBO
McAfee-GW-EditionFareit-FQZ!2820F8605681
FortinetW32/EJYJ.FQZ!tr
Trapminemalicious.high.ml.score
FireEyeTrojan.GenericKD.42253091
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
F-ProtW32/Injector.XD.gen!Eldorado
MAXmalware (ai score=89)
ArcabitTrojan.Generic.D284BB23
ZoneAlarmTrojan-Spy.Win32.Xegumumune.dbj
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34082.hm0@aSXchofG
ALYacGen:Variant.Razy.599867
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.WACATAC.THAAFBO
TencentWin32.Trojan-spy.Xegumumune.Hprs
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.42253091
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan-Spy.Win32.Xegumumune.dbj?

Trojan-Spy.Win32.Xegumumune.dbj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment