Backdoor

Backdoor.Agent.MS removal instruction

Malware Removal

The Backdoor.Agent.MS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.MS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself

How to determine Backdoor.Agent.MS?


File Info:

name: ACF2D0A6287625BA2BA0.mlw
path: /opt/CAPEv2/storage/binaries/288f8433064b1a2b21c30efdcc493de05df10402b8c1d8e9f7119141f63385cd
crc32: 6C89D40F
md5: acf2d0a6287625ba2ba0a759899fceba
sha1: 4986201091109f82c93c33e60cdedfc71ec48d8e
sha256: 288f8433064b1a2b21c30efdcc493de05df10402b8c1d8e9f7119141f63385cd
sha512: 95b827090c83ca262c1cdcfcef2dac6b277c6a12ce27630a9055324bd316e8c5877c082d098a432b2356f409884fea899c7502e0de590d6e67dc2edf11c065a5
ssdeep: 3072:byVkg5aMnqR6rBXiPB1JXLD1wAKVP1Iv6OkSB5WhsIZ6MmJXRPctB:byr5aKFyJ1JbmDN1Iv6ELmmJXRP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AF5019483534621C44F8AF5E2A3C5915336BF43ABD39F3E89E508A9E7D31419E2AB24
sha3_384: 0edfd5eb8625f7074ce783d7d28ecf703184eac4c8bbdf3081a72e5274e6741aba57e7b816c9678f1b5cf82e3926c15e
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-02-20 16:27:48

Version Info:

Translation: 0x0000 0x04b0
Comments: Z8Wyttrxgo
CompanyName: wPmlEsvlPo
FileDescription: 72hBC13fGk
FileVersion: 2.3.1.7
InternalName: xMyvnJF6N0.exe
LegalCopyright: Copyright © YVAnLApFRx 2014
LegalTrademarks: xiiOYdK7Jc
OriginalFilename: xMyvnJF6N0.exe
ProductName: xMyvnJF6N0
ProductVersion: 2.3.1.7
Assembly Version: 7.1.6.7

Backdoor.Agent.MS also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.25188
CynetMalicious (score: 100)
McAfeeGenericRXHG-GI!ACF2D0A62876
CylanceUnsafe
ZillyaTrojan.SelfDel.Win32.40875
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.628762
BitDefenderThetaGen:NN.ZemsilF.34062.np3@aOlt@Mi
ESET-NOD32a variant of MSIL/Injector.CUN
KasperskyTrojan.Win32.SelfDel.ariz
BitDefenderGen:Trojan.Mardom.IN.10
NANO-AntivirusTrojan.Win32.Blocker.ezgblz
MicroWorld-eScanGen:Trojan.Mardom.IN.10
AvastWin32:Malware-gen
Ad-AwareGen:Trojan.Mardom.IN.10
SophosML/PE-A
ComodoTrojWare.MSIL.Agent.SDF@58gxd9
FireEyeGeneric.mg.acf2d0a6287625ba
EmsisoftGen:Trojan.Mardom.IN.10 (B)
IkarusTrojan-Spy.MSIL
GDataGen:Trojan.Mardom.IN.10
JiangminTrojanSpy.MSIL.epg
AviraBDS/DarkKomet.cfes
Antiy-AVLTrojan/Generic.ASMalwS.13E6F35
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32Trojan.SelfDel
ALYacGen:Trojan.Mardom.IN.10
MAXmalware (ai score=86)
MalwarebytesBackdoor.Agent.MS
APEXMalicious
YandexTrojan.Injector!IO/cQWYLy5o
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_78%
FortinetMSIL/Injector.CVB!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.6941579.susgen

How to remove Backdoor.Agent.MS?

Backdoor.Agent.MS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment