Backdoor

Should I remove “Backdoor.Agent.PDL”?

Malware Removal

The Backdoor.Agent.PDL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.PDL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Detects Avast Antivirus through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

Related domains:

vivaliaremedies.com

How to determine Backdoor.Agent.PDL?


File Info:

crc32: 68E9F193
md5: 4102939c074e297b9fd3081349c9e5d9
name: Material Enquiry.gz
sha1: f04ddf7fa3d9ae3914b3888e917c6864c21e93e3
sha256: 473bbe4db5564aebb4011188abc186713729b3dcd204c58b6220b2e2b869ecd3
sha512: f474a043a7b716a83c1733fe7f170c7349a4cc8b392c1337a70c3c6b5dfb86a6042c28ab882d560252c07b7b16e2c9b0efb44c0df9f5dc58b8a465f5a6b15a5d
ssdeep: 6144:yYt6JOMs5WPxIXp6hx87NXxOMwZKUkPQULUJW9J:yYUJO552O9DOMwZhkoULUJA
type: Zip archive data, at least v2.0 to extract

Version Info:

0: [No Data]

Backdoor.Agent.PDL also known as:

MicroWorld-eScanGen:Variant.Zusy.164954
CAT-QuickHealTrojanPWS.Fareit.r3
ALYacGen:Variant.Zusy.164954
MalwarebytesBackdoor.Agent.PDL
VIPRETrojan.Win32.Generic!BT
K7GWTrojan ( 004d39d61 )
K7AntiVirusTrojan ( 004d39d61 )
AgnitumTrojan.PWS.Tepfer!a2oybWp14R4
F-ProtW32/MSIL_Injector.AQ.gen!Eldorado
ESET-NOD32a variant of MSIL/Injector.MEF
TrendMicro-HouseCallTSPY_FAREIT.Y
AvastMSIL:Stealer-AY [Trj]
GDataGen:Variant.Zusy.164954
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.164954
NANO-AntivirusTrojan.Win32.Tepfer.dxrhfs
RisingMSIL:Malware.Generic(Thunder)!1.A1C4 [F]
Ad-AwareGen:Variant.Zusy.164954
EmsisoftGen:Variant.Zusy.164954 (B)
ComodoUnclassifiedMalware
F-SecureGen:Variant.Zusy.164954
DrWebTrojan.MulDrop6.8961
ZillyaTrojan.Tepfer.Win32.84026
TrendMicroTSPY_FAREIT.Y
McAfee-GW-EditionBehavesLike.Trojan.dc
SophosMal/MSIL-OM
CyrenW32/MSIL_Injector.AQ.gen!Eldorado
JiangminBackdoor.DarkKomet.ln
Antiy-AVLTrojan[PSW]/Win32.Tepfer
ArcabitTrojan.Zusy.D2845A
ViRobotTrojan.Win32.A.PSW-Tepfer.265216.D[h]
MicrosoftPWS:Win32/Fareit
McAfeeRDN/Generic PWS.y
AVwareTrojan.Win32.Generic!BT
VBA32TrojanPSW.Tepfer
PandaTrj/CI.A
TencentWin32.Trojan.Generic.Oyek
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.MDY!tr
AVGMSIL9.KDU
Baidu-InternationalTrojan.MSIL.Injector.MEF

How to remove Backdoor.Agent.PDL?

Backdoor.Agent.PDL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment