Trojan

How to remove “Trojan.Win32.Mucc.rzh”?

Malware Removal

The Trojan.Win32.Mucc.rzh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Mucc.rzh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Mucc.rzh?


File Info:

crc32: CD7A7BA4
md5: cd65994e4f53363527e3651759103759
name: CD65994E4F53363527E3651759103759.mlw
sha1: 241dda06961d323299c19c1f558168864867169e
sha256: 634115d5eb91226011678443a96617cb0bcc1831621b418a0e16860b79502de7
sha512: 077473c0b90b1f41f2775a144909ca6c4edd1c1a03df92ece1de2637124d5e3ed903bb6073e81e486906fe2b00b472f2da75e40d5ddcfebe2dfd016d3d2d1583
ssdeep: 768:L/nxsMCmcp1FaKWg49kg8cf3hVFwal+HZL+J0d937yH38o5pjZ4vLJTX8HjlF8u:znxUH49NNf3hMDkeyX8qpjZc9oX8M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: MESALLIANCER
FileVersion: 1.00
CompanyName: Seismic
ProductName: HULKORTSOPERATRS
ProductVersion: 1.00
OriginalFilename: MESALLIANCER.exe

Trojan.Win32.Mucc.rzh also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Mucc.4!c
Elasticmalicious (high confidence)
ALYacTrojan.Agent.GuLoader
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Nekark.5879b228
K7GWTrojan-Downloader ( 005661971 )
K7AntiVirusTrojan-Downloader ( 005661971 )
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Agent.FCS
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Mucc.rzh
BitDefenderTrojan.GenericKD.37664003
ViRobotTrojan.Win32.Z.Agent.94208.GGA
MicroWorld-eScanTrojan.GenericKD.37664003
TencentWin32.Trojan.Mucc.Taor
Ad-AwareTrojan.GenericKD.37664003
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.ewqik@0
BitDefenderThetaGen:NN.ZevbaF.34170.fm0@amPJO!hb
McAfee-GW-EditionBehavesLike.Win32.Fareit.nm
FireEyeGeneric.mg.cd65994e4f533635
EmsisoftTrojan.GenericKD.37664003 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Mucc.r.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D23EB503
ZoneAlarmTrojan.Win32.Mucc.rzh
GDataTrojan.GenericKD.37664003
AhnLab-V3Trojan/Win.Generic.C4656719
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=88)
MalwarebytesTrojan.GuLoader
PandaTrj/GdSda.A
RisingTrojan.Injector!1.B459 (CLASSIC)
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent.FCS!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Mucc.rzh?

Trojan.Win32.Mucc.rzh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment