Backdoor

About “Backdoor.Agent.WU” infection

Malware Removal

The Backdoor.Agent.WU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.WU virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Backdoor.Agent.WU?


File Info:

crc32: 56E4595A
md5: 361665038c00a24d02e6211cb935904d
name: lol.exe
sha1: 76df83dd0951e12b204bcec7a1f03de5c7ccab51
sha256: 1ff2c6125a8e6741b7a6a8b9d53e5203401e85c5df0c138e3f7de3432723a411
sha512: 37dd43fcf56768d2fac2690e9734962bf242c89b5f17ec43b37a2db2836c44c9df9b3ebbb873857473986e68506838b7d4b9de03de2d1efa749255919050ae0b
ssdeep: 1536:phzxR0NcB1GqpFDSF75BNnj9JSE8yf3A:nzxYcBsqr0xnZJSE8yfQ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: 7XUIUTZDT54E22N
Assembly Version: 1.0.0.0
InternalName: lol.exe
FileVersion: 1.0.0.0
CompanyName: 0HHLBQJZPN701MU
LegalTrademarks: MYHH2JSKKV2F32H
Comments: RINYB4A9Y8WN72Q
ProductName: 7GEHNCA735ABZUR
ProductVersion: 1.0.0.0
FileDescription: ABOTD0V9Y06CS5E
OriginalFilename: lol.exe

Backdoor.Agent.WU also known as:

DrWebTrojan.DownLoader33.25725
MicroWorld-eScanGen:Variant.Razy.610832
FireEyeGeneric.mg.361665038c00a24d
ALYacGen:Variant.Razy.610832
CylanceUnsafe
K7AntiVirusTrojan ( 005360841 )
BitDefenderGen:Variant.Razy.610832
K7GWTrojan ( 005360841 )
Cybereasonmalicious.38c00a
BitDefenderThetaAI:Packer.14ACA15C1F
CyrenW32/Trojan.BKGY-6876
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Razy.610832
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
AlibabaTrojan:Win32/Starter.ali2000005
AegisLabTrojan.MSIL.Crysan.m!c
RisingBackdoor.Crysan!8.10ECA (CLOUD)
Ad-AwareGen:Variant.Razy.610832
SophosMal/Generic-S
ComodoMalware@#18z8xewreeu9s
F-SecureTrojan.TR/Dropper.MSIL.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Razy.610832 (B)
IkarusTrojan.MSIL.Crypt
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan[Backdoor]/MSIL.Crysan
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D95210
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3Malware/Win32.RL_Generic.C3542607
Acronissuspicious
McAfeeArtemis!361665038C00
MAXmalware (ai score=100)
MalwarebytesBackdoor.Agent.WU
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.ORX
TrendMicro-HouseCallTROJ_GEN.R03BH0CD120
TencentWin32.Trojan.Inject.Auto
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Crysan.ORX!tr.bdr
WebrootW32.Downloader.Gen
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Backdoor.c00

How to remove Backdoor.Agent.WU?

Backdoor.Agent.WU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment