Backdoor

Backdoor.Agent.BitRAT malicious file

Malware Removal

The Backdoor.Agent.BitRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.BitRAT virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.Agent.BitRAT?


File Info:

crc32: A4873547
md5: 52245de0b67a49befe656dec74b9344f
name: 52245DE0B67A49BEFE656DEC74B9344F.mlw
sha1: 1443306efc49c4820770fe0cde36c4ca68fdeda2
sha256: 6a28f7fb457fb484c1fbcceb41b10637345b18950b62df89c0a7689dd4f20d68
sha512: c81e6fe0393036e0e66a24190ccbb5a217bcbdf9ece8da9deb1120da87bc801a80692ff8bd788b765ce21e1a477fba23e4a11a4384da762b31bed99fa15b71f6
ssdeep: 98304:PVZWhDELQh4pAJ/mS3YN8HgIsYCXJtH6zpj2euVljJsPWW:PVZyNJ+isYCXz+YVl1GB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2021 voidtools
InternalName: Everythings
FileVersion: 1.4.1.2
CompanyName: voidstools
ProductName: Everythings
ProductVersion: 1.4.1.2
FileDescription: Everything
OriginalFilename: Everythings.exe
Translation: 0x0409 0x04b0

Backdoor.Agent.BitRAT also known as:

CynetMalicious (score: 85)
ALYacBackdoor.Agent.BitRAT
MalwarebytesBackdoor.BitRAT
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.36481153
K7GWTrojan ( 00569d2a1 )
ArcabitTrojan.Generic.D22CA881
CyrenW32/Trojan.SKBZ-0189
ESET-NOD32Win32/Agent.ACBZ
Paloaltogeneric.ml
AlibabaTrojan:Win32/Redcap.d8a7bf41
MicroWorld-eScanTrojan.GenericKD.36481153
RisingRansom.Crowti!8.37D (C64:YzY0Olx5mUwl9Sgw)
Ad-AwareTrojan.GenericKD.36481153
EmsisoftMalCert.A (A)
ComodoMalware@#2udfhiw0f18v3
F-SecureTrojan.TR/Redcap.psylu
DrWebTrojan.Inject4.8489
TrendMicroTROJ_FRS.VSNTCA21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.52245de0b67a49be
SophosMal/Generic-S
AviraTR/Redcap.psylu
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftTrojan:Win32/TopAntiSpyware!rfn
ViRobotTrojan.Win32.Z.Bitrat.3600360
GDataWin32.Backdoor.BitRAT.3F9IEK
McAfeeArtemis!52245DE0B67A
MAXmalware (ai score=84)
TrendMicro-HouseCallTROJ_FRS.VSNTCA21
IkarusTrojan.SuspectCRC
FortinetW32/Generik.SDMLDW!tr
WebrootW32.Malware.Gen
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
Qihoo-360Win32/Trojan.Generic.HgIASQgA

How to remove Backdoor.Agent.BitRAT?

Backdoor.Agent.BitRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment