Backdoor

About “Backdoor.Agent.PTCGen” infection

Malware Removal

The Backdoor.Agent.PTCGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.PTCGen virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Backdoor.Agent.PTCGen?


File Info:

name: 0C7DC1DD6BD910D05295.mlw
path: /opt/CAPEv2/storage/binaries/b9ef23d2758b17d44544721b570fde89b5e97c2547bd24476ccc172707057b3e
crc32: 1ED575D4
md5: 0c7dc1dd6bd910d05295e39a300de78f
sha1: 98baba551287167aa1db71012313eae06ce35ae0
sha256: b9ef23d2758b17d44544721b570fde89b5e97c2547bd24476ccc172707057b3e
sha512: 51bcc3d5135961118e3ced1bb985875574490f235397cb00b6f78a786e2e62c47125aedefb2aa1500ab91a275abd3dbad59d4273540e174225ff0cfe17b01ac6
ssdeep: 1536:8ZWHrjViOkwrPMH6CwTAhWPTfOVJqJTCrI5HrbEeR1XLs/1TEen2ot8R+OVpNsfb:mMD+w0hI708J20hou1XLsewtY3sfb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8B3121F3AB7C5A4DD4E0777E793C80A882A0A9B6171F27A96EC02625D41097D2F3DA4
sha3_384: a83571e81becf171deefce33e9c461f9ca2cf5ec4656f0c6bb2d20fa192a664bf59fdc3cfc7256c32a2aafe3a4708e19
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-10-30 15:35:49

Version Info:

Translation: 0x0000 0x04b0
Comments: ФоほуḔоḔ亊ひаくқӨẦẦϚззḔϐẦаЌふҼиかϚみま
CompanyName: けҼЏзьҶ五л難мЏЦえе亊аまϟяはほこъҼひдいубФ
FileDescription: ЊФоъϟбаえま骨ϐоөҼоЖお与мқЏώқḒал争おЗめ
FileVersion: 4665.3248.3248.3248
InternalName: Patch.exe
LegalCopyright: Copyright © いЌ事Њ難ほώẦ事亊ЦгдḆϐаҼЦひллḈḒбьъьЖまл 2324846654
LegalTrademarks: миаき事лいӨϚьふへҼ予ь亊ҍ難Ϛөみ亊оふひいӔ六Ќқ
OriginalFilename: Patch.exe
ProductName: Ц争оώくсъусけϟӔггЌмЦϟけзсмгうЖ頂ь与ωも
ProductVersion: 4665.3248.3248.3248
Assembly Version: 4665.3248.3248.3248

Backdoor.Agent.PTCGen also known as:

LionicTrojan.Win32.Generic.lX7F
DrWebBackDoor.Bladabindi.1393
MicroWorld-eScanGen:Variant.Razy.641671
FireEyeGeneric.mg.0c7dc1dd6bd910d0
McAfeeArtemis!0C7DC1DD6BD9
MalwarebytesBackdoor.Agent.PTCGen
VIPREGen:Variant.Razy.641671
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e39a1 )
AlibabaTrojanDropper:Win32/FrauDrop.ce04411b
K7GWTrojan ( 0055e39a1 )
Cybereasonmalicious.d6bd91
BitDefenderThetaGen:NN.ZemsilF.36662.hm0@aqetXJh
VirITTrojan.Win32.MSIL5.AQXJ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.ADY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.FrauDrop.ahinl
BitDefenderGen:Variant.Razy.641671
NANO-AntivirusTrojan.Win32.Drop.dijgtp
AvastMSIL:Agent-BMU [Trj]
TencentWin32.Trojan-Dropper.Fraudrop.Hplw
EmsisoftGen:Variant.Razy.641671 (B)
F-SecureHeuristic.HEUR/AGEN.1309861
ZillyaDropper.FrauDrop.Win32.20158
TrendMicroTROJ_GEN.R002C0GHO23
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL2
GDataGen:Variant.Razy.641671
JiangminTrojanDropper.FrauDrop.alqb
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1309861
Antiy-AVLTrojan[Dropper]/Win32.FrauDrop
XcitiumMalware@#1hm3sgv6gsuj6
ArcabitTrojan.Razy.D9CA87
ZoneAlarmTrojan-Dropper.Win32.FrauDrop.ahinl
MicrosoftBackdoor:MSIL/Bladabindi
GoogleDetected
ALYacGen:Variant.Razy.641671
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Chgt.J
TrendMicro-HouseCallTROJ_GEN.R002C0GHO23
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:TtqLF+rwvq/h6Igrtkkh/g)
YandexTrojan.Injector!fRocwmnd4cI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.BQZ!tr
AVGMSIL:Agent-BMU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Agent.PTCGen?

Backdoor.Agent.PTCGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment