Backdoor

Backdoor.Agent.P removal guide

Malware Removal

The Backdoor.Agent.P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.P virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

pastebin.com

How to determine Backdoor.Agent.P?


File Info:

crc32: E88F9B9A
md5: 9ecf54abbfa3d7c55df60e8a68850c95
name: 2.mp4
sha1: 80577ddc1a3b47a192ebc35137f34c6ba8d4173f
sha256: ea370a7b71aa91fd68429a7550b436689a9866d6988363f099c26f3ab3108033
sha512: 3b22cc1f9523ef74e66dd08322f3547081e3dbb9abf080eedc260be880033878466be86e0c926c0c94a168dc75b2849f84acd2c3b947fbd1a58a2128cc81a567
ssdeep: 384:8KsVPtjWOBY5pUvlJ1stkjZ7hKWPAoWFZDxfhNQ/e13X2kt5rRbr9ftwYGcl:8KgBY5pUv6qjZNnJyZDlMyj5Vdt2cl
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: j.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: j.exe

Backdoor.Agent.P also known as:

MicroWorld-eScanGen:Variant.Razy.284775
FireEyeGeneric.mg.9ecf54abbfa3d7c5
CylanceUnsafe
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.284775
K7GWTrojan ( 700000121 )
Cybereasonmalicious.bbfa3d
ArcabitTrojan.Razy.D45867
TrendMicroBKDR_BLADABI.SMC
BitDefenderThetaGen:NN.ZemsilF.34104.bm0@aeYGzrp
F-ProtW32/Revetrat.A.gen!Eldorado
ESET-NOD32a variant of MSIL/Bladabindi.AS
TrendMicro-HouseCallBKDR_BLADABI.SMC
ClamAVWin.Trojan.Generic-6417450-0
GDataGen:Variant.Razy.284775
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
Ad-AwareGen:Variant.Razy.284775
F-SecureTrojan.TR/ATRAPS.Gen
DrWebBackDoor.BladabindiNET.9
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
SentinelOneDFI – Malicious PE
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Razy.284775 (B)
APEXMalicious
CyrenW32/Revetrat.A.gen!Eldorado
AviraTR/ATRAPS.Gen
MicrosoftTrojan:Win32/Wacatac.C!ml
Endgamemalicious (high confidence)
AhnLab-V3Trojan/Win32.RL_Bladabindi.R273021
ZoneAlarmHEUR:Trojan-Spy.MSIL.Agent.gen
ALYacGen:Variant.Razy.284775
MAXmalware (ai score=80)
MalwarebytesBackdoor.Agent.P
eGambitTrojan.Generic
FortinetMSIL/Bladabindi.AS!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Agent.P?

Backdoor.Agent.P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment