Backdoor

Should I remove “Backdoor.Agent.Generic”?

Malware Removal

The Backdoor.Agent.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.Generic virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task by a long amount of time.
  • A process was set to shut the system down when terminated
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

Related domains:

123123231.xyz

How to determine Backdoor.Agent.Generic?


File Info:

crc32: 5E3DDE27
md5: c44b3a3de03745a06d214fe16532c927
name: cssrs.exe
sha1: ab64c093304cd168ad2d15ec7802b438bd476012
sha256: aecf027f0b1328ef51c201031065ef09b2a701f53fb33749ba33a1e79da0a164
sha512: 7cd4cd741ab52eaa18e9b7bc7676510136d51da367821c869b1fd3f6694a7ec06e1cdfe4565548774dae95248f970320fbfb413066402eab5b7113fa025d142a
ssdeep: 12288:D2ZNAUIqvCv3ZxlwdJMwGWnG1/+VP9As:Wbnve7lwdJMyG1/y
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: csrss.exe
FileVersion: 1.0.0.0
CompanyName: Client Server Runtime Process
LegalTrademarks:
Comments: Client Server Runtime Process
ProductName: Stub
ProductVersion: 1.0.0.0
FileDescription: Client Server Runtime Process
OriginalFilename: csrss.exe

Backdoor.Agent.Generic also known as:

MicroWorld-eScanTrojan.GenericKD.42836187
Qihoo-360Generic/Trojan.21a
McAfeeArtemis!C44B3A3DE037
CylanceUnsafe
AegisLabTrojan.MSIL.Crypt.4!c
SangforMalware
K7AntiVirusTrojan ( 005082b31 )
BitDefenderTrojan.GenericKD.42836187
K7GWTrojan ( 005082b31 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NNAVRKK
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:MSIL/Generic.51224bb2
ViRobotTrojan.Win32.Z.Wacatac.395264.A
TencentMsil.Trojan.Crypt.Swkp
Ad-AwareTrojan.GenericKD.42836187
EmsisoftTrojan.GenericKD.42836187 (B)
F-SecureTrojan.TR/ATRAPS.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FortinetMSIL/Crypt.NNAVRKK!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c44b3a3de03745a0
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
JiangminTrojan.MSIL.oiub
WebrootW32.Malware.Gen
AviraTR/ATRAPS.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/MSIL.Crypt
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28DA0DB
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
ALYacTrojan.GenericKD.42836187
MalwarebytesBackdoor.Agent.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0ACA20
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.42836187
BitDefenderThetaGen:NN.ZemsilF.34100.ym0@aWrEqim
AVGWin32:Trojan-gen
Cybereasonmalicious.3304cd
Paloaltogeneric.ml

How to remove Backdoor.Agent.Generic?

Backdoor.Agent.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment