Spy Trojan

UDS:Trojan-Spy.Win32.Xegumumune removal instruction

Malware Removal

The UDS:Trojan-Spy.Win32.Xegumumune is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Xegumumune virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine UDS:Trojan-Spy.Win32.Xegumumune?


File Info:

name: 8E562EA2F825FF2ECF80.mlw
path: /opt/CAPEv2/storage/binaries/101a735e151606ad40c8da4f7dbfcd44f22ac59b20ba1eb9adbf80ec67f6881b
crc32: 7EECA1FE
md5: 8e562ea2f825ff2ecf80ade3c95ffa2d
sha1: 26a51f98eae537cfa730c1b9b2bdc76f4fead0ed
sha256: 101a735e151606ad40c8da4f7dbfcd44f22ac59b20ba1eb9adbf80ec67f6881b
sha512: c4999b22fde450a81cd61cab4a54fb1b946df2c831992dd9d123c5db3b48013e53930baa11f51b0b746880b82452ea8c7428eb401d570dbf4133e513b528722a
ssdeep: 49152:a11lgntOt0YybWSAwCUrEIPvkChYq2bK+HHOdFp3cRqOqN61ibqn:azlggRybWSA36EabhYdbK+Mp3xb62y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEC5338A1ECF7444F1769E344C22FBD888E4AC92D238981E67E4522576F2F4CC46777A
sha3_384: 1550a6a4614ffe8206a90d71ae80bcd3c6459aa161631029d89a247e28c6e1e32adc06640bfb5be437adffc84810a2cc
ep_bytes: eb08009a05000000000060e800000000
timestamp: 2004-08-04 06:01:37

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Reservados todos los derechos.
OriginalFilename: WEXTRACT.EXE
ProductName: Sistema operativo Microsoft® Windows®
ProductVersion: 6.00.2900.2180
Translation: 0x0c0a 0x04b0

UDS:Trojan-Spy.Win32.Xegumumune also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Xegumumune.l!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.8e562ea2f825ff2e
SkyhighBehavesLike.Win32.Virut.vc
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Packed.Enigma.CE
APEXMalicious
KasperskyUDS:Trojan-Spy.Win32.Xegumumune
AvastFileRepMalware [Bd]
TencentWin32.Trojan.Dropper.Gjgl
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
Trapminemalicious.high.ml.score
IkarusTrojan.Win64.Enigma
GoogleDetected
AviraTR/Dropper.Gen
Kingsoftmalware.kb.a.958
MicrosoftTrojan:Win32/Caynamer.A!ml
CynetMalicious (score: 100)
McAfeeArtemis!8E562EA2F825
VBA32BScope.Trojan.Wacatac
MalwarebytesGeneric.Malware/Suspicious
ZonerProbably Heur.ExeHeaderL
RisingSpyware.Xegumumune!8.10962 (CLOUD)
YandexTrojan.GenAsa!Z1dtqm+03ME
AVGFileRepMalware [Bd]
DeepInstinctMALICIOUS

How to remove UDS:Trojan-Spy.Win32.Xegumumune?

UDS:Trojan-Spy.Win32.Xegumumune removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment