Backdoor

Backdoor.Agent.AAIL removal tips

Malware Removal

The Backdoor.Agent.AAIL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.AAIL virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Backdoor.Agent.AAIL?


File Info:

name: 4AD863F3EC2D75233570.mlw
path: /opt/CAPEv2/storage/binaries/1713120b6b01d819e65276a41c3ceec156ef49858a455b664abc0421fa98f36d
crc32: 878F31F1
md5: 4ad863f3ec2d752335700d679ae279e3
sha1: 101ceeaacfcbdc261ccbf6f4dc193b8f75a4084c
sha256: 1713120b6b01d819e65276a41c3ceec156ef49858a455b664abc0421fa98f36d
sha512: 31ef445b9a7e9de23780bc26cfc9bfae31deaad5f63230431386697ba114f1fd1898e7eca00304535cc5f5c1feabcdce3cb23d88146c52d1fafcf61592a2937d
ssdeep: 768:hadbRpCWtbgr+jdYbtK+EvWCOkwhr38fSRWk1HI9aunS11F+tMgpt6:hibDJbygmbtEvW5qSwk1HI9NSAOot6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0E37D1275D1C8B3E64640760829CB65A73BBD021F7BC8937B992BCE4E753D1A23B346
sha3_384: c9613e8929b97d3267d467854c6dffe9842cd2492ae3e92dda5643583865117dc22008e5ce322666f6ca0d16e20d2f88
ep_bytes: e80e1f0000e917feffff558bec81ec28
timestamp: 2055-05-25 18:10:40

Version Info:

0: [No Data]

Backdoor.Agent.AAIL also known as:

MicroWorld-eScanBackdoor.Agent.AAIL
FireEyeGeneric.mg.4ad863f3ec2d7523
SkyhighBehavesLike.Win32.Generic.cz
MalwarebytesTrojan.Proxy
ZillyaTrojan.Agent.Win32.78240
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitBackdoor.Agent.AAIL
BitDefenderThetaGen:NN.ZexaF.36680.jqZ@amjBjyh
VirITTrojan.Win32.DownLoader2.CNAT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanProxy.Agent.NFQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-570208
KasperskyTrojan-Proxy.Win32.Agent.bua
BitDefenderBackdoor.Agent.AAIL
NANO-AntivirusTrojan.Win32.Agent.djozv
AvastWin32:WrongInf-F [Susp]
TencentMalware.Win32.Gencirc.11bb5425
TACHYONTrojan-Proxy/W32.Agent.147456.C
EmsisoftBackdoor.Agent.AAIL (B)
VIPREBackdoor.Agent.AAIL
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Menti
JiangminTrojanProxy.Agent.bfq
Antiy-AVLTrojan[Proxy]/Win32.Agent
KingsoftWin32.Virut.ce.57344
MicrosoftTrojan:Win32/Caynamer.A!ml
ZoneAlarmTrojan-Proxy.Win32.Agent.bua
GDataBackdoor.Agent.AAIL
GoogleDetected
AhnLab-V3Trojan/Win.Agent.C5579270
ALYacBackdoor.Agent.AAIL
MAXmalware (ai score=82)
Cylanceunsafe
PandaGeneric Malware
RisingTrojan.Dynamer!8.3A0 (TFE:5:YJgq5Xh33qM)
YandexTrojan.GenAsa!VCjhxd6USvs
SentinelOneStatic AI – Malicious PE
AVGWin32:WrongInf-F [Susp]
Cybereasonmalicious.acfcbd
DeepInstinctMALICIOUS

How to remove Backdoor.Agent.AAIL?

Backdoor.Agent.AAIL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment