Trojan

Trojan.Win32.Blamon.uxy malicious file

Malware Removal

The Trojan.Win32.Blamon.uxy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Blamon.uxy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs

How to determine Trojan.Win32.Blamon.uxy?


File Info:

crc32: 0A0CAB2F
md5: 89687d78f86639971b5b3336b6495011
name: 89687D78F86639971B5B3336B6495011.mlw
sha1: 831c5e4694739f0e0a245f503c12d461f0eb8968
sha256: a381ba5c4b61bfb7ba438a29b7d0dc4197165a6bcad8ddafeb85bd7ddaf48b10
sha512: a0a728884960c5d62b5a9633eb3f5320141897538be3dfbf102b5d405d444e894e714c5b536e66734f0b3f6448b580b7f67531430b1731bf6f86a4fc01aa5305
ssdeep: 49152:c7/FU7tBNLRYrVcVU73Bbo+cOeVx6eH/:cONNO3BbfNeVxZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Win32.Blamon.uxy also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Generic-9820446-0
CylanceUnsafe
SangforTrojan.Win32.PSE.11B5R9D
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Blamon.uxy
SophosGeneric PUA ID (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34170.TnGfaq1m6Dgb
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.89687d78f8663997
SentinelOneStatic AI – Malicious PE
AviraTR/Blamon.xapki
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.11B5R9D
AhnLab-V3Trojan/Win.Malware-gen.C4641381
Acronissuspicious
McAfeeArtemis!89687D78F866
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.2164980524
TrendMicro-HouseCallTROJ_GEN.R070H0CIN21
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/FlyStudio
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Blamon.uxy?

Trojan.Win32.Blamon.uxy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment