Backdoor

How to remove “Backdoor.dcRAT”?

Malware Removal

The Backdoor.dcRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.dcRAT virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor.dcRAT?


File Info:

name: 497C81D4177C2F2C0724.mlw
path: /opt/CAPEv2/storage/binaries/c66c491bf92e6185a293fc73cd26e06310a956eaacc05fe0c719b8936fa002c6
crc32: 6784749E
md5: 497c81d4177c2f2c0724b57da4e3beca
sha1: 331318b838da6f6db936ae0b228128aeda40b070
sha256: c66c491bf92e6185a293fc73cd26e06310a956eaacc05fe0c719b8936fa002c6
sha512: c426bec6d35daaf4771b4258b3116cd8dc2eff2fe31cef19566af8f1835bebce25e24bd53834f65649cbd3ccbacaee9165660d87ef926f9d1d0729225dac5147
ssdeep: 49152:UbA303Ji7JDaYvCx9yNAgs8HHfaSPMM2yraDuqJXn73nwCKFBF313ciGg867/:UbjOuZ8HHV2yuDxXTwCKHp5GW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6E5E0027E84CA11F4191777C2FF560847B4AC906AA6E31B7ABA776E15123937C4CECB
sha3_384: 3046cee041959f95410845c8a6d23424a293fc5989bc184748f17d7d4082f1a2c7b7f8957da24195d82fc31723844797
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Backdoor.dcRAT also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Makop.trQA
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.39864320
FireEyeTrojan.GenericKD.39864320
McAfeeArtemis!497C81D4177C
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0058ebd51 )
AlibabaBackdoor:MSIL/Remcos.4c67c030
K7GWSpyware ( 0058ebd51 )
Cybereasonmalicious.4177c2
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Basic-9952747-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.39864320
NANO-AntivirusTrojan.Win32.Stealer.jpsipr
AvastWin32:RATX-gen [Trj]
TencentWin32.Backdoor.Agent.Azlw
Ad-AwareTrojan.GenericKD.39864320
SophosMal/Generic-S + Mal/RarMal-R
ComodoMalware@#b05mrylz0sfa
F-SecureHeuristic.HEUR/AGEN.1203070
DrWebTrojan.PWS.StealerNET.124
VIPRETrojan.GenericKD.39864320
TrendMicroTROJ_GEN.R002C0RFN22
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.GenericKD.39864320 (B)
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.BSE.1CL7UZW
AviraVBS/Runner.VPG
Antiy-AVLTrojan[Spy]/MSIL.Stealer
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2604800
ViRobotTrojan.Win32.Z.Agent.3189490
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Uztuby.C5179306
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34806.Vs0@aaftqVfi
ALYacBackdoor.RAT.DC
MAXmalware (ai score=100)
VBA32Backdoor.dcRAT
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0RFN22
RisingBackdoor.DcRat!8.129D9 (CLOUD)
YandexTrojanSpy.Agent!XDN2zeO6QUc
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.1728101.susgen
FortinetMSIL/Agent.DVA!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.dcRAT?

Backdoor.dcRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment