Spy Trojan

TrojanSpy:Win32/Tougle.G!bit information

Malware Removal

The TrojanSpy:Win32/Tougle.G!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Tougle.G!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/Tougle.G!bit?


File Info:

crc32: 9D5ED22E
md5: 0ab7f62c052590a65e55b581aa04303a
name: 0AB7F62C052590A65E55B581AA04303A.mlw
sha1: 22f445b2ce6be1ee754531864092ca7c4e818b18
sha256: 1a1c7c91124012e179ce0334f0c4d6eda2ef76fb7660ac461f276ef917a4042d
sha512: efc7e85a3ab7d5514788adf98e7e9fad979031bf99b0e0dea3c2c1fd5e864cd5ca96680168b6bc1a4f73e8d2cf93c8691d959a53e9873f143e554e84cc09a469
ssdeep: 6144:jW/xeXQZS8Bp2aqCSZLPeAaN5wZ3hq8BxIaARSrXPPAACA15+sJlcg4P:exyW2TJbUN5wZ3hVhAWXPPAvC7w
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Tougle.G!bit also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051c1311 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.48145
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.333941
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1301774
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaMalware:Win32/km_24545.None
K7GWTrojan ( 0051c1311 )
Cybereasonmalicious.c05259
CyrenW32/S-ad63a1d0!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FZAQ
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Malware.Dangeroussig-6803894-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.333941
NANO-AntivirusTrojan.Win32.Kryptik.euytej
MicroWorld-eScanGen:Variant.Zusy.333941
TencentWin32.Trojan.Generic.Hzb
Ad-AwareGen:Variant.Zusy.333941
SophosMal/Generic-S (PUA)
ComodoTrojWare.Win32.Tougle.FZ@7edocf
BitDefenderThetaGen:NN.ZexaF.34236.2qW@aq16p7qQ
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FOTD!0AB7F62C0525
FireEyeGeneric.mg.0ab7f62c052590a6
EmsisoftGen:Variant.Zusy.333941 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.ahyf
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.22A84EF
MicrosoftTrojanSpy:Win32/Tougle.G!bit
GDataGen:Variant.Zusy.333941
AhnLab-V3Trojan/Win32.Ekstak.R213280
Acronissuspicious
McAfeeGenericRXDF-GJ!0AB7F62C0525
MAXmalware (ai score=99)
VBA32BScope.Trojan.Skeeyah
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
RisingSpyware.Voltar!1.AF1D (CLASSIC)
YandexTrojan.GenAsa!rtvppALQekY
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FZAQ!tr
AVGWin32:BackdoorX-gen [Trj]
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Tougle.G!bit?

TrojanSpy:Win32/Tougle.G!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment