Backdoor

What is “Backdoor.Agent.NIPGen”?

Malware Removal

The Backdoor.Agent.NIPGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.NIPGen virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Backdoor.Agent.NIPGen?


File Info:

name: FCC7A166DA3DA1A3506C.mlw
path: /opt/CAPEv2/storage/binaries/17a0f54249c83e8b2a476ebe885395a09f01af42371dc502b6a1ade440ff017e
crc32: 757BF8C5
md5: fcc7a166da3da1a3506c5294e12f6137
sha1: c376b3e1d144cabfbb73efe7746a50a7588c7fac
sha256: 17a0f54249c83e8b2a476ebe885395a09f01af42371dc502b6a1ade440ff017e
sha512: 107994392297093830116fdcaadd4d8f641c6df039f7252c5b779f685b293a7b1073bd105077bd06230cb19df4c1d1e13a749013be8bb709588bc5bdcc64ef08
ssdeep: 6144:2e/Fc/0BjPcb6GZce/Fc/0BjPcb6GZce/Fc/0BjPcb6GZce/Fc/0BjPcb6GZce/1:zBaRBaRBaRBaRBaRBaRBaRBaRBaRBa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11695BF8273449A16C67C6771C062C252A3B1BC860EA3EF1E6CD8BEEB0F767510B47957
sha3_384: 3b9329c114d61b9d6c1cb8bafc6743d95cec40f2cf40b27454a4b6fad65c5d653ceb7bfe9a426492eb1aaee9bca19296
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-10-02 22:40:17

Version Info:

0: [No Data]

Backdoor.Agent.NIPGen also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.7386
FireEyeGeneric.mg.fcc7a166da3da1a3
CAT-QuickHealWorm.Necast.J3
McAfeeTrojan-FIGN
CylanceUnsafe
ZillyaTrojan.Agent.Win32.358455
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.6da3da
ArcabitIL:Trojan.MSILZilla.D1CDA
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AZ
APEXMalicious
ClamAVWin.Trojan.B-468
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.7386
NANO-AntivirusTrojan.Win32.Autoruner.ctqpfj
AvastMSIL:Agent-CIB [Trj]
Ad-AwareIL:Trojan.MSILZilla.7386
EmsisoftIL:Trojan.MSILZilla.7386 (B)
ComodoTrojWare.MSIL.Spy.Agent.EF@4r4nna
DrWebBackDoor.BladabindiNET.12
VIPREWorm.MSIL.Necast.j (v)
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosML/PE-A + Mal/MSIL-GL
SentinelOneStatic AI – Malicious PE
JiangminTrojan/MSIL.gkjb
AviraTR/Agent.5587925
Antiy-AVLTrojan/Generic.ASMalwS.37A2C0
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AJ
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataIL:Trojan.MSILZilla.7386
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Palevo.C111399
ALYacIL:Trojan.MSILZilla.7386
MAXmalware (ai score=80)
VBA32Trojan.MSIL.Agent
MalwarebytesBackdoor.Agent.NIPGen
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingTrojan.Agent!1.9DB7 (CLASSIC)
YandexTrojan.Agent!EjboCgdFi7Q
IkarusBackdoor.MSIL
MaxSecureTrojan.MSIL.Bladabindi.b
FortinetMSIL/Agent.PPV!tr
BitDefenderThetaAI:Packer.822AA1F81F
AVGMSIL:Agent-CIB [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Agent.NIPGen?

Backdoor.Agent.NIPGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment