Backdoor

Backdoor.DCRat removal instruction

Malware Removal

The Backdoor.DCRat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.DCRat virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.DCRat?


File Info:

crc32: DAFD4CF8
md5: df64af933dfaf7aa30570cc9239f9168
name: c9675be9896d63f4d3020729f4f2bddd854a7000.exe
sha1: 70f44dc2e7b918dea69ee962d01ce9b0da0b25b5
sha256: 98b13d8d760055f2471072c97e60ee6cc9cf8b3daab2765cbe29a64894b5a0b5
sha512: dc3a373544054bf7a24e4c6142446e4209595021aa650e7f0af4847b4b4b3e5c47c841a2a294e8db90a24ee799a1cefda1658e7b51e8294d5cbd58461561e344
ssdeep: 49152:2+XvFDhff7eSR6FKnp2AThMm30yLWdOnB1N1lj2sTiHeQAvN:jBtgnATl3zLWcnRj2s+AN
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor.DCRat also known as:

MicroWorld-eScanTrojan.GenericKD.32993287
FireEyeGeneric.mg.df64af933dfaf7aa
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXJO-BH!DF64AF933DFA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.lXNp
SangforMalware
K7AntiVirusTrojan ( 0054f7ba1 )
BitDefenderTrojan.GenericKD.32993287
K7GWTrojan ( 0054f7ba1 )
Cybereasonmalicious.33dfaf
TrendMicroTROJ_GEN.R002C0WAS20
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Rasftuby-7369445-0
GDataTrojan.GenericKD.32993287
KasperskyTrojan.Win32.Vasal.akk
AlibabaTrojan:Win32/Vasal.0e6058f0
TencentWin32.Trojan.Vasal.Wugy
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32993287 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1041002
DrWebTrojan.PWS.Stealer.27916
ZillyaTrojan.Vasal.Win32.23
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUPXDE.vc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Rasftuby
CyrenW32/Trojan.OANE-8344
AviraHEUR/AGEN.1041002
MAXmalware (ai score=81)
ArcabitTrojan.Generic.D1F77007
ZoneAlarmTrojan.Win32.Vasal.akk
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Dropper/Win32.RL_Agent.R266317
Acronissuspicious
VBA32Trojan.Vasal
ALYacTrojan.GenericKD.32993287
Ad-AwareTrojan.GenericKD.32993287
MalwarebytesBackdoor.DCRat
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Enigma.CC
TrendMicro-HouseCallTROJ_GEN.R002C0WAS20
eGambitUnsafe.AI_Score_100%
FortinetW32/Enigma.CC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/HEUR/QVM11.1.D58F.Malware.Gen

How to remove Backdoor.DCRat?

Backdoor.DCRat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment