Backdoor

How to remove “Backdoor.Erica.2”?

Malware Removal

The Backdoor.Erica.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Erica.2 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes

How to determine Backdoor.Erica.2?


File Info:

crc32: 88201690
md5: bd458377cbc9d9b9ce5102ca0b11ac12
name: lolaso.exe
sha1: 00c1fd8a2c66f06f85e162e21da81d4e9495d816
sha256: f38e4a34c44d89d69f9946705998754d59c0e14a45704a9213a768c715ff2bf8
sha512: 4e70c9744cc8e5354c34954d1d32791ca5001c0c706a8f736d20d2e384e8ce8ec9e1af84655efb6ac0e8defc89b615f94964798146244cf2f705b40e8161b811
ssdeep: 6144:9yGlkbBKi44ZZNNkHERdMvX2kxOE2cuSuXoLq6Z:VyQi44ZNjj4PIE2Jw
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: 14njibh5.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: 14njibh5.exe

Backdoor.Erica.2 also known as:

DrWebTrojan.PackedNET.8
MicroWorld-eScanGen:Variant.Backdoor.Erica.2
CAT-QuickHealVirTool.Obfuscator.AM5
ALYacGen:Variant.Backdoor.Erica.2
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0053564e1 )
BitDefenderGen:Variant.Backdoor.Erica.2
K7GWTrojan ( 0053564e1 )
Cybereasonmalicious.7cbc9d
BitDefenderThetaGen:NN.ZemsilF.34106.tq0@a4kQmSj
CyrenW32/MSIL_Troj.CD.gen!Eldorado
APEXMalicious
GDataGen:Variant.Backdoor.Erica.2
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Variant.Backdoor.Erica.2
EmsisoftGen:Variant.Backdoor.Erica.2 (B)
ComodoTrojWare.MSIL.Injector.DKR@7ixht8
F-SecureTrojan.TR/Dropper.Gen
BaiduMSIL.Trojan.Injector.u
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bd458377cbc9d9b9
SophosTroj/MSIL-ECK
IkarusTrojan.Injector
F-ProtW32/MSIL_Troj.CD.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dropper.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Backdoor.Erica.2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/GenKryptik.PJ!ibt
AhnLab-V3Win-Trojan/MSILKrypt14.Exp
Acronissuspicious
McAfeePWSZbot-FACM!BD458377CBC9
MAXmalware (ai score=87)
ESET-NOD32a variant of MSIL/Injector.YN
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Injector.PE!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.DC38.Malware.Gen

How to remove Backdoor.Erica.2?

Backdoor.Erica.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment