Backdoor

About “Backdoor.Agent.RAT.Generic” infection

Malware Removal

The Backdoor.Agent.RAT.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.RAT.Generic virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor.Agent.RAT.Generic?


File Info:

name: 254B0BE0CFB639A0AFF3.mlw
path: /opt/CAPEv2/storage/binaries/3277597800403b9ce8507eb6a04fc0daa23c6b2a9bd6d78bcacd152f172744e9
crc32: 14D47C0C
md5: 254b0be0cfb639a0aff36af57e35829d
sha1: 379cf3a4410a12348f58fd1fbf3aa9b03bc4921e
sha256: 3277597800403b9ce8507eb6a04fc0daa23c6b2a9bd6d78bcacd152f172744e9
sha512: 23566aa7f83a01b51ac8be880d199cfaf82dc8042025720ee0f73cb8d8e553d8cdaf011abd447ffa4ffae2329c56fbf282b6490c6ac5230e1971ab7036aba63f
ssdeep: 3072:ywkusEUMAwOE0RqwbZ+g9Fo6R1LJh5W+Yc+lXpPSLSho97OG/ZNIbo0N:d1sEUUOE0oiZ+g9Fo6Rzh5W+Yc+tpPS+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117F30D99123183B4E417C4392BE45BC85B7C9E25405F9F98A6DE8B36BFA2F354D02EC4
sha3_384: 45df0f40cc2b760930ead33090026e91e0cdb74874daa020995e64c3bdd257e6754fe68207c9ce57d7b631b9b09131d4
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-04 15:10:43

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: devlim.exe
LegalCopyright:
OriginalFilename: devlim.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Backdoor.Agent.RAT.Generic also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Stealer.l!c
CynetMalicious (score: 100)
CAT-QuickHealTrojanSpy.MSIL
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPREGen:Variant.Tedy.157594
SangforInfostealer.Msil.Agent.V2da
K7AntiVirusTrojan-Downloader ( 005992401 )
K7GWTrojan-Downloader ( 005992401 )
Cybereasonmalicious.4410a1
CyrenW32/Bladabindi.DJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.NQF
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderGen:Variant.Tedy.157594
MicroWorld-eScanGen:Variant.Tedy.157594
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:6Ycp3V8gICEyboEmdVCk7Q)
Ad-AwareGen:Variant.Tedy.157594
EmsisoftGen:Variant.Tedy.157594 (B)
F-SecureHeuristic.HEUR/AGEN.1234960
TrendMicroTROJ_GEN.R002C0GJ722
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.254b0be0cfb639a0
SophosML/PE-A
IkarusTrojan.MSIL.Vmprotect
GDataGen:Variant.Tedy.157594
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1234960
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.3CE9
ArcabitTrojan.Tedy.D2679A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.RealProtect-LS.C5270668
Acronissuspicious
ALYacGen:Variant.Tedy.157594
MalwarebytesBackdoor.Agent.RAT.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0GJ722
TencentMsil.Trojan-Downloader.Ader.Adhl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34698.km0@aSVH7B
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AD
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Agent.RAT.Generic?

Backdoor.Agent.RAT.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment