Backdoor

About “Backdoor.Agent” infection

Malware Removal

The Backdoor.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Backdoor.Agent?


File Info:

crc32: 422C7B49
md5: 3266feb35d1eaa9697dd2e000b0ce18c
name: kam.exe
sha1: 9808c7321101e02f1c016c5726fc212ca727a2f7
sha256: f695f5b135b5254122d1c4613b5f470f5f021853d7e03dd82b52be19586d1e2f
sha512: af0609f62a0c0df528ba3b433933825a737f6c0be0345297ee3259598b20180dd950f1309b933174cd61b20d623018421800d85459ca5819fc4471827931c4da
ssdeep: 49152:ycN67XE1hz/zPkQEhc12PEV1Ywc8AWL321ZMihj3NOm+5SyE2hrh4PyxeNr5XaFk:yJoh3UFMV1pA12ihRO5EKq649ZG4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: QEOUZMZKVJ
FileVersion: 1.7.2.1
CompanyName: QEOUZMZKVJ
LegalTrademarks: QEOUZMZKVJ
Comments: QEOUZMZKVJ
ProductName: QEOUZMZKVJQEOUZMZKVJ
FileDescription: QEOUZMZKVJ
Translation: 0x0409 0x04e4

Backdoor.Agent also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.41958431
FireEyeTrojan.GenericKD.41958431
CAT-QuickHealTrojan.Scrami
McAfeeArtemis!3266FEB35D1E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Scrami.4!c
SangforMalware
BitDefenderTrojan.GenericKD.41958431
K7GWTrojan ( 0055681f1 )
K7AntiVirusTrojan ( 0055681f1 )
ArcabitTrojan.Generic.D2803C1F
TrendMicroTROJ_GEN.R002C0GJV19
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/RA-based.NIS
TrendMicro-HouseCallTROJ_GEN.R002C0GJV19
AvastWin32:DangerousSig [Trj]
GDataTrojan.GenericKD.41958431
KasperskyHEUR:Trojan.Win32.Scrami.gen
AlibabaTrojan:Win32/based.e1d7def1
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftAdware.Agent (A)
ComodoMalware@#126oio5sjztff
F-SecureHeuristic.HEUR/AGEN.1042347
DrWebTrojan.StartPage1.58172
McAfee-GW-EditionArtemis!Trojan
SentinelOneDFI – Malicious PE
SophosMal/Generic-S
APEXMalicious
CyrenW32/Trojan.OVVQ-6022
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1042347
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3PUP/Win32.RL_Agent.R293607
ZoneAlarmHEUR:Trojan.Win32.Scrami.gen
ALYacTrojan.Agent.Scrami
MAXmalware (ai score=89)
VBA32Trojan.Scrami
MalwarebytesBackdoor.Agent
PandaTrj/CI.A
FortinetW32/RA.NIZ!tr
Ad-AwareTrojan.GenericKD.41958431
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.02c

How to remove Backdoor.Agent?

Backdoor.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment