Backdoor

About “Backdoor.Agent.PDL.Generic” infection

Malware Removal

The Backdoor.Agent.PDL.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.PDL.Generic virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Detects Avast Antivirus through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyipaddress.com

How to determine Backdoor.Agent.PDL.Generic?


File Info:

crc32: 2CC874E4
md5: 4d8c38d0658d922461b8c36d968df506
name: 4D8C38D0658D922461B8C36D968DF506.mlw
sha1: cf2df52d68c490e1daa9a8e75de3da9f9ef16e98
sha256: f914891a1bd3b55aaa1af8dd26be81064fa7cbb300d3babb1cd7df36009bc388
sha512: 36f846b4db2afb7ffec8baf045f79f2b56713bb4dda577cbfec8582d7d7517222994cc62a3c2b210575617d3d391e31757e68d13cd06dc2e81338ea12d538394
ssdeep: 6144:0AnHqc16JgLEr0hN/NYpeBSxBAE9CDefD3K34rBRiPqEhJ5D/448j28dj:LemIrCSrT9QURiPdJ5Dgv
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016
Assembly Version: 3.21.5864.38123
InternalName: Carpati.exe
FileVersion: 3.21.5864.38123
CompanyName: newcompany.sa
Comments:
ProductName: Carpati
ProductVersion: 3.21.5864.38123
FileDescription: Carpati
OriginalFilename: Carpati.exe
Translation: 0x0410 0x04b0

Backdoor.Agent.PDL.Generic also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Ubibila.1
FireEyeGeneric.mg.4d8c38d0658d9224
CAT-QuickHealTrojan.MultiFC.S18288075
ALYacGen:Heur.MSIL.Ubibila.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004dc5b41 )
BitDefenderGen:Heur.MSIL.Ubibila.1
K7GWTrojan ( 004dc5b41 )
Cybereasonmalicious.0658d9
BitDefenderThetaGen:NN.ZemsilF.34804.Dm0@aKOK@emG
CyrenW32/MSIL_Injector.BF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.NSR
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Ubibila.enwkep
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Heur.MSIL.Ubibila.1
SophosML/PE-A + Troj/MSIL-FLF
ComodoMalware@#169fgovhxyp33
F-SecureHeuristic.HEUR/AGEN.1101057
DrWebTrojan.PWS.Siggen1.45817
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftGen:Heur.MSIL.Ubibila.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Heye.dr
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1101057
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.MSIL.Ubibila.1
AhnLab-V3Trojan/Win32.MDA.R173394
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan.Injector.FL
CynetMalicious (score: 100)
Acronissuspicious
McAfeeFareit-FDB!4D8C38D0658D
MalwarebytesBackdoor.Agent.PDL.Generic
PandaTrj/GdSda.A
RisingTrojan.Dynamer!8.3A0 (TFE:C:deAq7wyotzC)
YandexTrojan.Agent!ELC+MaKOi/c
IkarusTrojan.MSIL.Injector
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Injector.NLR!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.Malware.Gen

How to remove Backdoor.Agent.PDL.Generic?

Backdoor.Agent.PDL.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment