Backdoor

Backdoor.Agent.IMN malicious file

Malware Removal

The Backdoor.Agent.IMN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.IMN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes

Related domains:

dnstrafficexchange.duckdns.org

How to determine Backdoor.Agent.IMN?


File Info:

crc32: EF83023C
md5: 9e50b249c984b02ffe52d469a05396f2
name: vbc.exe
sha1: 5cc5ebd1ea59c61910e3672bad25ef2bba79e474
sha256: 5e106d7b95627d982862e8d97f9b057632427008df0b994cd4b99e17c41a4c26
sha512: 8c8533699f010e266b9284315a60ad8b806d6f6e331198fc492364a8dca7e87007529885d6eb986328c84498383fcc6f4e76c4376e466c37e3e46c0fb5bfbc0f
ssdeep: 6144:+Y6yVbWCcK0f1pmGZt8Y3ACX7v9Rs/RFLoC:+Y6y1W00NEU8f8v9m9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2013
Assembly Version: 1.0.0.0
InternalName: 1.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
Comments: Description
ProductName: ClientProduct
ProductVersion: 1.0.0.0
FileDescription: Client
OriginalFilename: 1.exe

Backdoor.Agent.IMN also known as:

MicroWorld-eScanGeneric.MSIL.PasswordStealerA.BE823801
FireEyeGeneric.mg.9e50b249c984b02f
CAT-QuickHealHackTool.Boilod.AP3
McAfeeHTool-Immirat
CylanceUnsafe
ZillyaTrojan.Immirat.Win32.482
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.PasswordStealerA.BE823801
K7GWTrojan ( 700000121 )
Cybereasonmalicious.9c984b
TrendMicroBKDR_BLADABINDI.SM
BaiduMSIL.Trojan.Injector.ae
F-ProtW32/MSIL_Troj.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Immirat-A [Trj]
GDataMSIL.Backdoor.Imminent.A
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:MSIL/Boilod.62565b28
NANO-AntivirusTrojan.Win32.Agent.edcvtj
RisingBackdoor.Immirat!8.1117B (CLOUD)
Endgamemalicious (high confidence)
SophosMal/MSIL-AZ
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.KeyLogger.28086
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionHTool-Immirat
Trapminemalicious.high.ml.score
EmsisoftGeneric.MSIL.PasswordStealerA.BE823801 (B)
IkarusTrojan.MSIL.Injector
CyrenW32/MSIL_Troj.L.gen!Eldorado
JiangminTrojan/Generic.bhigo
MaxSecureTrojan.Malware.7164915.susgen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
ArcabitGeneric.MSIL.PasswordStealerA.BEDC91F9
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Boilod.A
AhnLab-V3Trojan/Win32.Dynamer.R136503
ALYacGeneric.MSIL.PasswordStealerA.BE823801
MAXmalware (ai score=85)
Ad-AwareGeneric.MSIL.PasswordStealerA.BE823801
MalwarebytesBackdoor.Agent.IMN
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Immirat.B
TrendMicro-HouseCallBKDR_BLADABINDI.SM
TencentWin32.Trojan.Generic.Hvsq
YandexTrojan.Agent!vroS5XgYo38
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Immirat.B!tr
BitDefenderThetaGen:NN.ZemsilF.34100.wm0@aKzJO5d
AVGWin32:Immirat-A [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM03.0.1BC3.Malware.Gen

How to remove Backdoor.Agent.IMN?

Backdoor.Agent.IMN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment