Backdoor

Backdoor.Agent.DCGen removal guide

Malware Removal

The Backdoor.Agent.DCGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.DCGen virus can do?

  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

Related domains:

redirector.gvt1.com
r3—sn-4g5ednsd.gvt1.com

How to determine Backdoor.Agent.DCGen?


File Info:

crc32: 39B93D75
md5: 0aa21b5566c709414b6dfd546349b757
name: 0AA21B5566C709414B6DFD546349B757.mlw
sha1: 71a7af1ba380b262b956ea762517ed12dfc037da
sha256: dd85466f766052764d971dc2d37d11edc1cfeb6ce2301f0d90f4ea2792500ca0
sha512: 59728814deeaa57f1616955e411e0c8e6f3ca8a5844d6e69132c9a129c7a671a4152785dec553b9ff3bc88b5095e31bcb2139e17c1fcb0233d4f797bbdd98e03
ssdeep: 12288:lVS98HGGjx1/BFvJ12OmgVbmHxxhvcFC:lVS98HtF15V2nOmHx7vX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: privprot.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: privprot.exe

Backdoor.Agent.DCGen also known as:

MicroWorld-eScanGen:Variant.Razy.651240
FireEyeGeneric.mg.0aa21b5566c70941
ALYacGen:Variant.Razy.651240
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0053564e1 )
BitDefenderGen:Variant.Razy.651240
K7GWTrojan ( 0053564e1 )
Cybereasonmalicious.566c70
BitDefenderThetaGen:NN.ZemsilF.34804.zm0@am@RG9f
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastMSIL:GenMalicious-BNB [Trj]
KasperskyHEUR:Trojan-Downloader.Win32.Generic
AlibabaTrojanDownloader:MSIL/Injector.73f7f346
NANO-AntivirusTrojan.Win32.EPX.dhxvjt
TencentMsil.Trojan.Dropper.Hpa
Ad-AwareGen:Variant.Razy.651240
EmsisoftGen:Variant.Razy.651240 (B)
ComodoTrojWare.MSIL.Ceatrg.RJIK@5nq15g
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Siggen2.48773
ZillyaWorm.Shakblades.Win32.2523
TrendMicroTROJ_GEN.R06CC0RJK20
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosML/PE-A + Troj/MSIL-AAG
IkarusTrojan.MSIL6
JiangminWorm/Shakblades.wr
AviraTR/ATRAPS.Gen
Antiy-AVLWorm/Win32.Shakblades
KingsoftWin32.Troj.Generic_a.c.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.Razy.D9EFE8
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataGen:Variant.Razy.651240
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C568195
Acronissuspicious
McAfeeArtemis!0AA21B5566C7
MAXmalware (ai score=100)
VBA32Worm.Shakblades
MalwarebytesBackdoor.Agent.DCGen
PandaTrj/Chgt.G
ESET-NOD32a variant of MSIL/Injector.EPX
TrendMicro-HouseCallTROJ_GEN.R06CC0RJK20
YandexTrojan.Injector!qrnEjcnJUGA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.EPX!tr
AVGMSIL:GenMalicious-BNB [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/Malware.QVM03.Gen

How to remove Backdoor.Agent.DCGen?

Backdoor.Agent.DCGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment