Backdoor

Backdoor.AsyncRAT malicious file

Malware Removal

The Backdoor.AsyncRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.AsyncRAT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Backdoor.AsyncRAT?


File Info:

crc32: ABC0B43D
md5: 2e74f75f9d574d04cf218bdce47759c0
name: tmpi_sefpd2
sha1: e43a894d9aa15964a8ce1185d8e617f1c4cfa5bb
sha256: e424f88be2ecb08fbe022e3e6f4988c0275b63f7480fad0be8c0ec1e24405f41
sha512: d2ef237380691234eb4c02a2b6df333f63c45600ace13d667ccc5c77d093162330cb3d23b1f30c851da528d34221f9cd9d829bae0f758bb6da8d202335470cc1
ssdeep: 24576:JAHnh+eWsN3skA4RV1Hom2KXSmda8KohdK00Eayf5:Qh+ZkldoPKi2a8KohYR6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor.AsyncRAT also known as:

FireEyeGeneric.mg.2e74f75f9d574d04
Qihoo-360Win32/Trojan.Dropper.a7e
McAfeeArtemis!2E74F75F9D57
CylanceUnsafe
SangforMalware
AlibabaTrojanDropper:Win32/Kpavtoit.4de2bac0
ArcabitTrojan.Generic.D294F839
SymantecTrojan Horse
APEXMalicious
CynetMalicious (score: 85)
KasperskyTrojan-Dropper.Win32.Kpavtoit.ut
BitDefenderTrojan.GenericKD.43317305
Paloaltogeneric.ml
AegisLabHacktool.Win32.Gamehack.3!e
MicroWorld-eScanTrojan.GenericKD.43317305
RisingTrojan.Obfus/Autoit!1.C646 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43317305 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
SophosMal/Generic-S
AviraTR/AD.Inject.djawo
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmTrojan-Dropper.Win32.Kpavtoit.ut
GDataMSIL.Backdoor.ASyncRAT.S2S1ED
AhnLab-V3Malware/Win32.Possible_smhpnegastealb.C4081529
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.43317305
MalwarebytesBackdoor.AsyncRAT
ESET-NOD32a variant of Win32/Injector.Autoit.FIJ
TrendMicro-HouseCallTROJ_GEN.R002H06F920
IkarusTrojan-Spy.Keylogger.AgentTesla
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Injector.FIC!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.AsyncRAT?

Backdoor.AsyncRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment