Backdoor

Should I remove “Backdoor.Asruex”?

Malware Removal

The Backdoor.Asruex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Asruex virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Asruex?


File Info:

crc32: BBF0401B
md5: 4f2e4e6bb81b8df810200e626ec077d5
name: 4F2E4E6BB81B8DF810200E626EC077D5.mlw
sha1: 6f060b4fc0aec6f47244d103418d2dbe9e38c247
sha256: 89e55e84166c33b9700b754c1e7a141b3c652b3227c4f60efe34a7baf0acf209
sha512: 2eb655a3cc391dc489f09901f05d1713a92d5d5d7f3639cdb705cfbf8448730f2768fda9586b2ec13bbd4ddb8236a9c049d5a72f919d9cd514189e529da746a8
ssdeep: 49152:zITZznMFqsg5Q7DXBMKGeX5OENWSWKYJkwTz:zErqqsg5GDXBhDXIENbWKIx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998-2001 ANDO ELECTRIC CO.,LTD. Copyright (C) 2003-2011 D.I Corporation
InternalName: Tbt
FileVersion: 9, 0, 5, 14
CompanyName: D.I Corporation
ProductName: AF8650TBT 32 BIT CONTROLLER
ProductVersion: 9, 0, 5, 14
FileDescription: Test burn-in test system
OriginalFilename: Tbt.exe
Translation: 0x0409 0x04b0

Backdoor.Asruex also known as:

BkavW32.FamVT.TaidoorY.Trojan
K7AntiVirusTrojan ( 001761171 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader21.55939
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentbRI.S7708105
ALYacGen:Variant.Mikey.115547
CylanceUnsafe
ZillyaTrojan.Agent.Win32.689590
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Agentb.c30b0eeb
K7GWTrojan ( 001761171 )
Cybereasonmalicious.bb81b8
CyrenW32/S-37d21855!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Agent.RGR
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Agentb-9808245-0
KasperskyTrojan.Win32.Agentb.bsps
BitDefenderGen:Variant.Mikey.115547
NANO-AntivirusTrojan.Win32.Agent.ejpkdx
ViRobotTrojan.Win32.Agent.869376.I
MicroWorld-eScanGen:Variant.Mikey.115547
TencentMalware.Win32.Gencirc.10b8acda
Ad-AwareGen:Variant.Mikey.115547
SophosML/PE-A
BitDefenderThetaAI:Packer.FB931EBD21
TrendMicroPE_ASRUEX.A
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.4f2e4e6bb81b8df8
EmsisoftGen:Variant.Mikey.115547 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.biz
AviraTR/Crypt.XPACK.Gen4
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Asruex.A
GridinsoftTrojan.Win32.Agent.bot!s1
GDataGen:Variant.Mikey.115547
AhnLab-V3Trojan/Win32.Agentb.R196717
Acronissuspicious
McAfeeGenericRXIQ-HA!4F2E4E6BB81B
MAXmalware (ai score=80)
VBA32Trojan.Agentb
MalwarebytesBackdoor.Asruex
PandaTrj/CI.A
TrendMicro-HouseCallPE_ASRUEX.A
RisingVirus.Asruex!1.CC86 (CLASSIC)
YandexTrojan.GenAsa!kLLWd0Qcw70
IkarusTrojan.Win32.Asruex
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.17284B2!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Asruex?

Backdoor.Asruex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment