Backdoor

Backdoor.Agent.ABHW removal guide

Malware Removal

The Backdoor.Agent.ABHW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.ABHW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Starts servers listening on 0.0.0.0:21
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

supnewdmn.com
tvrstrynyvwstrtve.com
rtvwerjyuver.com
wqerveybrstyhcerveantbe.com

How to determine Backdoor.Agent.ABHW?


File Info:

crc32: CA91FD3B
md5: ebc35bf5774a4b75cd45638cecb74db3
name: EBC35BF5774A4B75CD45638CECB74DB3.mlw
sha1: 3a4858d3ab2074b6d2d5a999a7443c683af2417b
sha256: 52c970b575040b26c6c357f1aa64288544578a229b9be70acd0f860f55cca346
sha512: 365feb8dccdbf66ff9dd5e1aa08126b0c6da0cb1fe6cf7a986cbb6c66928f7c3282492c11946598652e18fa695f7ea7021cd3f5943a20650e9efe829a0891ca1
ssdeep: 1536:zOC0FvV4OguHxjhpA4Bm7uW0vSUsghQevBFkutIbgTuFqKRr0aF5frleGhd9TfB:zwV4OgSzBmh04eZFkz3Rr0gwGj9Tf8
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor.Agent.ABHW also known as:

BkavW32.InjectAdwaredDwnMainA.Trojan
TotalDefenseWin32/Pakes.EA!genus
MicroWorld-eScanBackdoor.Agent.ABHW
nProtectTrojan/W32.Agent.135680.GD
CMCTrojan.Win32.Pakes!O
CAT-QuickHealTrojan.Agen.rw3
ALYacBackdoor.Agent.ABHW
MalwarebytesBackdoor.IRCBot
ZillyaTrojan.PornoBlocker.Win32.2280
K7AntiVirusTrojan ( 0038b1be1 )
K7GWTrojan ( 0038b1be1 )
TheHackerTrojan/Kryptik.amn
BaiduWin32.Trojan.Pakes.a
CyrenW32/Bamital.N.gen!Eldorado
SymantecTrojan.Bamital!gen2
ESET-NOD32Win32/Ramnit.A
TrendMicro-HouseCallTROJ_FAKEAV.SMUP
ClamAVWin.Virus.Lockscreen-56
KasperskyTrojan-Ransom.Win32.PornoBlocker.anbz
BitDefenderBackdoor.Agent.ABHW
NANO-AntivirusTrojan.Win32.MulDrop3.dxpbhf
ViRobotTrojan.Win32.Z.Pakes.135680[h]
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
Ad-AwareBackdoor.Agent.ABHW
SophosW32/Ramnit-A
ComodoTrojWare.Win32.Agent.kwsr
F-SecureBackdoor.Agent.ABHW
DrWebTrojan.MulDrop3.45645
VIPRETrojan.Win32.Encpk.aak (v)
TrendMicroTROJ_FAKEAV.SMUP
McAfee-GW-EditionBehavesLike.Win32.Ramnit.ch
EmsisoftBackdoor.Agent.ABHW (B)
F-ProtW32/Bamital.N.gen!Eldorado
JiangminTrojan/PornoBlocker.bmn
Antiy-AVLTrojan/Win32.Pakes.tyi
MicrosoftTrojan:Win32/Ramnit.A
ArcabitBackdoor.Agent.ABHW
AegisLabTroj.Ransom.W32.PornoBlocker.kfc!c
GDataBackdoor.Agent.ABHW
AhnLab-V3Trojan/Win32.Bamital.N299786360
McAfeeGeneric BackDoor.ya
AVwareTrojan.Win32.Encpk.aak (v)
VBA32Trojan.Pakes
ZonerWorm.Ramnit.AY
TencentTrojan.Win32.Pakes.aac
YandexTrojan.Kryptik!2KhajVvOffQ
IkarusTrojan.Win32.Pakes
FortinetW32/Drooptroop.SMY!tr
AVGGeneric22.BPCM
PandaGeneric Malware
Qihoo-360Worm.Win32.FakeFolder.BU

How to remove Backdoor.Agent.ABHW?

Backdoor.Agent.ABHW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment