Backdoor

Backdoor.Agent.PDLGen malicious file

Malware Removal

The Backdoor.Agent.PDLGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.PDLGen virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients

How to determine Backdoor.Agent.PDLGen?


File Info:

crc32: 857B9B87
md5: 6310da29e3c9d8606ce05e96ae4fbcff
name: 6310DA29E3C9D8606CE05E96AE4FBCFF.mlw
sha1: a75c9e7c7b3fa2988c960260f01ab746ea3ba228
sha256: 1a44a0bc93d4f829404adb03337d66684593f764c8cc959f2a0c80d6cd56bbba
sha512: aa8ad9036e165afec6b91c2757c2af60c9e0937cf08231d537b344d2d0804cb5b396858d0b2eadf3ccaf914ce23ae371ed8859dc6f176fe15d5c40a9322b798f
ssdeep: 6144:jSrawA/kU4eYKLBa0eqWeOUb2qdjYbMIOL1B41uAXROPoBJOpOnnnnnnnnnnnnn:jSrLA/9jeqaUb2quMIOL741uHQBQ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 12.610.0.0
CompanyName: Salfeld Computer GmbH
Comments: This installation was built with Inno Setup.
ProductName: Child Control
ProductVersion: 12.610.0.0
FileDescription: Credential Manager
Translation: 0x0409 0x04b0

Backdoor.Agent.PDLGen also known as:

K7AntiVirusTrojan ( 005700491 )
LionicTrojan.Win32.Pakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen1.31846
CynetMalicious (score: 99)
ALYacTrojan.PasswordStealer.GenericKD.32055378
CylanceUnsafe
ZillyaTrojan.Pakes.Win32.36923
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:MSIL/Injector.e32aa3d6
K7GWTrojan ( 005700491 )
Cybereasonmalicious.9e3c9d
BaiduMSIL.Trojan.Injector.am
SymantecInfostealer.Isurbal
ESET-NOD32a variant of MSIL/Injector.JWC
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.PasswordStealer.GenericKD.32055378
NANO-AntivirusTrojan.Win32.Pakes.dshyug
MicroWorld-eScanTrojan.PasswordStealer.GenericKD.32055378
TencentWin32.Trojan.Generic.Wlfc
Ad-AwareTrojan.PasswordStealer.GenericKD.32055378
SophosMal/Generic-R + Mal/MSIL-OM
ComodoMalware@#1d0awu8czleuy
BitDefenderThetaGen:NN.ZemsilF.34236.Cm0@a8MlpBpi
VIPRETrojan.Win32.Pakes
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.6310da29e3c9d860
EmsisoftTrojan.PasswordStealer.GenericKD.32055378 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1128797
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.11368CA
KingsoftWin32.Troj.Unknown.c.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.PasswordStealer.Generic.D1E92052
GDataTrojan.PasswordStealer.GenericKD.32055378
AhnLab-V3Spyware/Win32.Limitail.R150294
McAfeeRDN/Generic PWS.y!b2c
MAXmalware (ai score=100)
VBA32Trojan.Pakes
MalwarebytesBackdoor.Agent.PDLGen
PandaTrj/CI.A
YandexTrojan.Pakes!6VT1k0s56Fg
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.KER!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Agent.PDLGen?

Backdoor.Agent.PDLGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment