Backdoor

Backdoor.Agent.DNGen removal tips

Malware Removal

The Backdoor.Agent.DNGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.DNGen virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Agent.DNGen?


File Info:

crc32: CF4B7B40
md5: 9b98a4a56d39e4d2e6dc0fb6dc8cde9d
name: 9B98A4A56D39E4D2E6DC0FB6DC8CDE9D.mlw
sha1: b4fd642ff32fec117031cc892092eaa6895a9134
sha256: 04251934551079aff0e56bd2c60897e4fb8c38fde9f89ff71f28b656708268ec
sha512: 164639aebfb53be901acfd684d09092e6fc2795e17ae34e347644b9d4fa1da58841ca472fa58c73326b12c585aab80a682d1838316b1a470ea0b4fc941b9589c
ssdeep: 3072:P56vBuJYPwXaqQmENuVTmd4EE+cZ/oSaG:PcBuJYEaqffVA+Zo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor.Agent.DNGen also known as:

DrWebTrojan.Nanocore.23
CynetMalicious (score: 100)
ALYacGen:Variant.MSIL.Mensa.11
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/NanoCore.6e2e2fc5
Cybereasonmalicious.56d39e
CyrenW32/MSIL_Kryptik.BWB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.CUZ
APEXMalicious
AvastMSIL:GenMalicious-ADH [Trj]
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.MSIL.Mensa.11
NANO-AntivirusTrojan.Win32.Drop.cwxrdl
MicroWorld-eScanGen:Variant.MSIL.Mensa.11
Ad-AwareGen:Variant.MSIL.Mensa.11
SophosML/PE-A + Troj/MSIL-BHT
ComodoTrojWare.MSIL.Injector.DVA@7drt0w
BitDefenderThetaGen:NN.ZemsilF.34690.gmW@aS1aPdj
VIPREWorm.MSIL.Gamarue.d (v)
TrendMicroTROJ_GEN.R005C0DEG21
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.9b98a4a56d39e4d2
EmsisoftGen:Variant.MSIL.Mensa.11 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:MSIL/NanoCore.MR!MTB
GDataGen:Variant.MSIL.Mensa.11
Acronissuspicious
McAfeeTrojan-FNEO!9B98A4A56D39
MAXmalware (ai score=86)
MalwarebytesBackdoor.Agent.DNGen
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R005C0DEG21
RisingTrojan.NanoCore!8.527 (CLOUD)
IkarusBackdoor.Win32.DarkKomet
FortinetMSIL/Injector.CSZ!tr
AVGMSIL:GenMalicious-ADH [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Agent.DNGen?

Backdoor.Agent.DNGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment