Trojan

Should I remove “Trojan:Win32/Tapxamy.A”?

Malware Removal

The Trojan:Win32/Tapxamy.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tapxamy.A virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Tapxamy.A?


File Info:

crc32: 72621A67
md5: da86bc553702ba8ef0fa7ae571c9f80e
name: fdc26953d7d86654.exe
sha1: 3aff671e3d828811f21589187497c22ab5760a11
sha256: 3317e46eb0a7a4e95b56b4ece77a78c02ee85c99c1e4dd305fc2f4f87c57496e
sha512: a2125ecd1ea68aab64b280f3bf70edb4eb66aae6488dfebb6f9d364994acbe03fec89f7eb79ff3a41855771fc962aa464395f01f2f7fba4cb30cc2b9def49436
ssdeep: 49152:B8LgFs8EmU99ou7Bi+L75mwfxyniLSZ+KP2glcacO:B8LgFslT77MQf8niWMSZUO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: PatchUi.exe
FileVersion: 2, 0, 3, 1013
CompanyName: x98d8x4e91x9601x5b98x65b9x8bbax575b
Comments: Www.ChinaPYG.CoM
ProductName: PatchUi
ProductVersion: 2, 0, 3, 1013
FileDescription: Baymax Patcher Tools
OriginalFilename: PatchUi.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Tapxamy.A also known as:

MicroWorld-eScanGen:Variant.Mikey.96130
FireEyeGen:Variant.Mikey.96130
CAT-QuickHealTrojan.Tapxamy
ALYacGen:Variant.Mikey.96130
CylanceUnsafe
BitDefenderGen:Variant.Mikey.96130
K7GWUnwanted-Program ( 005221181 )
K7AntiVirusUnwanted-Program ( 005221181 )
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Mikey.96130
AlibabaTrojan:Win32/Tapxamy.341949ab
AegisLabTrojan.Win32.Mikey.4!c
RisingTrojan.HijcLpk!1.998A (CLOUD)
Ad-AwareGen:Variant.Mikey.96130
EmsisoftGen:Variant.Mikey.96130 (B)
ComodoMalware@#3hf55lvlz28oa
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DDP19
McAfee-GW-EditionGenericR-PRP!DA86BC553702
SophosGeneric PUA BK (PUA)
IkarusPUA.DllInject
CyrenW32/Trojan.WITS-7857
WebrootW32.Trojan.Gen
MAXmalware (ai score=94)
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Mikey.D17782
SUPERAntiSpywareTrojan.Agent/Gen-Mikey
MicrosoftTrojan:Win32/Tapxamy.A
AhnLab-V3Malware/Win32.Generic.C3157926
McAfeeGenericR-PRP!DA86BC553702
VBA32BScope.Trojan.Wintrim
MalwarebytesRiskWare.Injector
PandaTrj/CI.A
ESET-NOD32a variant of Win32/DllInject.IZ potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DDP19
TencentWin32.Trojan.Gen.Wtdm
YandexRiskware.Agent!
SentinelOneDFI – Suspicious PE
FortinetRiskware/DllInject
AVGWin32:Malware-gen
Cybereasonmalicious.53702b
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.0bb

How to remove Trojan:Win32/Tapxamy.A?

Trojan:Win32/Tapxamy.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment