Backdoor

What is “Backdoor.Agent.DarkRAT”?

Malware Removal

The Backdoor.Agent.DarkRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.DarkRAT virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Backdoor.Agent.DarkRAT?


File Info:

crc32: 2E99649E
md5: 339800289e29184eef7c6436b5e7e9dd
name: guc.exe
sha1: 6376defdde7ad1d66435a404d53d22fa300e9e91
sha256: 785162637380f917a4f3a187ab532a1f0d408ff892324af32c6d962ecf2d67db
sha512: 693a8043cb0cd0cab0c16ab58ba71ad06649c5c8542778101202c1ff134ecd17e6dbc93b0a9d0d226e54033a59bcd6d02de5d5e2f9372a3da74ac5d84a138f7b
ssdeep: 6144:mJ3QlXostZZ/NdY8rYLEI0TYI5O5BElojUjlQsAUUwvONJ41FaiAOzh4oA9:mJanF1dpI0Th5O5BqojUuqvONJw7vo9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Agent.DarkRAT also known as:

MicroWorld-eScanGen:Variant.Ulise.83754
FireEyeGeneric.mg.339800289e29184e
CAT-QuickHealBackdoor.Agent
McAfeeRDN/Generic.fzt
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00554ceb1 )
BitDefenderGen:Variant.Ulise.83754
K7GWTrojan ( 00554ceb1 )
Cybereasonmalicious.89e291
Invinceaheuristic
F-ProtW32/Ursu.CW.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DarkRAT.A
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyBackdoor.Win32.Agent.mytqkf
AlibabaBackdoor:Win32/Agent.2863b39f
NANO-AntivirusTrojan.Win32.DarkRAT.gbdvvu
RisingBackdoor.Darkrat!1.BACF (CLASSIC)
Ad-AwareGen:Variant.Ulise.83754
EmsisoftGen:Variant.Ulise.83754 (B)
ComodoMalware@#21dzshk4jzy6g
DrWebTrojan.MulDrop10.41402
ZillyaTrojan.DarkRAT.Win32.8
TrendMicroBackdoor.Win32.DARKRAT.THJODAI
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosMal/Generic-S
IkarusTrojan.Win32.Darkrat
CyrenW32/Trojan.KCRT-5792
JiangminAdWare.StartSurf.xxe
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1042363
FortinetW32/DarkRAT.A!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D1472A
ZoneAlarmBackdoor.Win32.Agent.mytqkf
MicrosoftBackdoor:Win32/DarkRAT.AR!MTB
AhnLab-V3Malware/Win32.Generic.C3458631
Acronissuspicious
BitDefenderThetaGen:Trojan.Heur.FU.vuW@aKzUMngi
ALYacBackdoor.Agent.DarkRAT
MAXmalware (ai score=83)
VBA32Trojan.MulDrop
MalwarebytesBackdoor.DarkRat
PandaGeneric Malware
TrendMicro-HouseCallBackdoor.Win32.DARKRAT.THJODAI
YandexBackdoor.Agent!0loA8cqwSYg
SentinelOneDFI – Malicious PE
GDataGen:Variant.Ulise.83754
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.426

How to remove Backdoor.Agent.DarkRAT?

Backdoor.Agent.DarkRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment