Trojan

Should I remove “Trojan:Win32/LummaC.ASGF!MTB”?

Malware Removal

The Trojan:Win32/LummaC.ASGF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LummaC.ASGF!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the MetaStealer malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/LummaC.ASGF!MTB?


File Info:

name: A0959F7B12BF5690CAEB.mlw
path: /opt/CAPEv2/storage/binaries/7fce2e30b5bf52ee7979ddec397784b1b4c51ae57f0d0dec16a3d7a88f8afd75
crc32: ADA017CC
md5: a0959f7b12bf5690caebba58321672e5
sha1: 48081627b8ef18bd418aa866d95ba2119a176b61
sha256: 7fce2e30b5bf52ee7979ddec397784b1b4c51ae57f0d0dec16a3d7a88f8afd75
sha512: 1843a8692082c36597701aa8e835b47d2aa77745724864072123af435bce7f245aa4c3c5b419f5be298aba11413b5ef46b466891f8d6e3a6ea38c3cac32adda4
ssdeep: 6144:LBQ4J4ZgQBW643RESjJZHGaZfb11cf4aSJq3+d6esKAUKgXRa:m4J4ZH65jJZHrb1JM++KhKgXRa
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E854CF1575C0C072D5B325321AF4DBB89F7DF9304AA66E9F57D40FAE4F30282C621A6A
sha3_384: b271144a0b063886d74ef8e481719444aef90d46107a5e1213781c1d91ff954a2d6f7d722c9eda9aefd024d4c28df700
ep_bytes: e8f4060000e974feffff558bec8b4508
timestamp: 2024-04-25 21:31:29

Version Info:

0: [No Data]

Trojan:Win32/LummaC.ASGF!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Lazy.6715
FireEyeGeneric.mg.a0959f7b12bf5690
SkyhighBehavesLike.Win32.Generic.dc
McAfeeArtemis!A0959F7B12BF
MalwarebytesMalware.AI.3407671267
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GWZJ
APEXMalicious
TrendMicro-HouseCallMal_Locky-1
KasperskyHEUR:Trojan-PSW.Win32.Lumma.gen
BitDefenderGen:Variant.Ser.Lazy.6715
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Ser.Lazy.6715 (B)
F-SecureTrojan.TR/Kryptik.vbbwh
DrWebTrojan.PWS.Stealer.38634
TrendMicroMal_Locky-1
Trapminesuspicious.low.ml.score
SophosML/PE-A
AviraTR/Kryptik.vbbwh
Antiy-AVLTrojan[PSW]/Win32.Lumma
MicrosoftTrojan:Win32/LummaC.ASGF!MTB
ArcabitTrojan.Ser.Lazy.D1A3B
ZoneAlarmHEUR:Trojan-PSW.Win32.Lumma.gen
GDataGen:Variant.Ser.Lazy.6715
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Locky.R646425
BitDefenderThetaGen:NN.ZexaF.36804.sCW@aSpYmnbi
ALYacGen:Variant.Lazy.519172
RisingTrojan.Generic@AI.100 (RDML:4×7+EEInTHyQlHu8ZiKZVg)
MAXmalware (ai score=86)
FortinetW32/Kryptik.RDLN!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/LummaC.ASGF!MTB?

Trojan:Win32/LummaC.ASGF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment