Backdoor

How to remove “Backdoor.Generic.200288”?

Malware Removal

The Backdoor.Generic.200288 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.200288 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Generic.200288?


File Info:

name: 4FB23495193E4F4CEDD9.mlw
path: /opt/CAPEv2/storage/binaries/5caec0c61c21ad4f33d967a395ff249ff9ace51080a6b938154adf7897de0336
crc32: 0872030C
md5: 4fb23495193e4f4cedd9e57f004c3cc0
sha1: 6aa8a0bd3959301694a2fb22ce6e07da22d2d1ab
sha256: 5caec0c61c21ad4f33d967a395ff249ff9ace51080a6b938154adf7897de0336
sha512: 5b95056d55dfb9cc243778931d471a4502b942c12bfeb10d4b769620c162c35f34609967935d3cd3f42958bd8b4cb5ade61c58c7c0e1acd44d02b54e264ec521
ssdeep: 6144:iw+oeBbqy5d5SKVGzLSNnHFASbL98HuSoKBe6qZlhXcF0P:c1bqy5z8zG1HFA1HuHdxMi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C540185F5438FB0D4599B304A73CF1E2B33FC25B846264BA7943B9A2DF7292192705B
sha3_384: fb69fec967ff15f0a75fe004d4f7a36bccd5f01cd00e453f977213c1202223a10c51fef453a6b5aabfd0d216d1d67971
ep_bytes: 558becb9080000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Generic.200288 also known as:

BkavW32.UkuranB.Worm
LionicVirus.Win32.Nakuru.to0W
tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Generic.200288
ClamAVWin.Trojan.Agent-1179472
FireEyeGeneric.mg.4fb23495193e4f4c
CAT-QuickHealW32.Nakuru.A8
McAfeeW32/Kespo.a
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.Nakuru.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3e61 )
AlibabaVirus:Win32/Nakuru.2b58dd13
K7GWTrojan ( 0055e3e61 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Virus.Nakuru.a
VirITWorm.Win32.Delf.HCT
CyrenW32/Backdoor.QFOU-0053
SymantecW32.Tupofse.B!inf
Elasticmalicious (high confidence)
ESET-NOD32Win32/Delf.AXZ
ZonerTrojan.Win32.32831
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Nakuru.a
BitDefenderBackdoor.Generic.200288
NANO-AntivirusTrojan.Win32.Hesv.itombk
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.Nakuru.a
EmsisoftBackdoor.Generic.200288 (B)
F-SecureTrojan.TR/Drop.Loops.A.1
DrWebWin32.HLLP.Kespo
VIPREBackdoor.Generic.200288
TrendMicroPE_KESPO.C
McAfee-GW-EditionW32/Kespo.a
Trapminemalicious.moderate.ml.score
SophosTroj/Bckdr-QIX
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1GIKWQS
JiangminTrojan/Delf.if
WebrootW32.Malware.Gen
AviraTR/Drop.Loops.A.1
Antiy-AVLVirus/Win32.Nakuru.a
XcitiumBackdoor.Win32.Delf.AXZ@2sfg
ArcabitBackdoor.Generic.D30E60
ViRobotWin32.Nakuru.A
ZoneAlarmVirus.Win32.Nakuru.a
MicrosoftVirus:Win32/Nakuru.A
GoogleDetected
AhnLab-V3Trojan/Win32.Xema.C113396
BitDefenderThetaGen:NN.ZelphiF.36662.rGZ@aG@jSHai
ALYacBackdoor.Generic.200288
MAXmalware (ai score=100)
VBA32Backdoor.Delf
Cylanceunsafe
PandaTrj/Ukurka.B
TrendMicro-HouseCallPE_KESPO.C
RisingVirus.Win32.Nakuru.a (CLASSIC)
YandexTrojan.GenAsa!crAYjzJGleo
IkarusVirus.Win32.Nakuru
MaxSecureVirus.Nakuru.A
FortinetW32/Nakuru.A
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor.Generic.200288?

Backdoor.Generic.200288 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment