Backdoor

Backdoor.Generic.293659 removal instruction

Malware Removal

The Backdoor.Generic.293659 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.293659 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor.Generic.293659?


File Info:

name: 9CBC2ACD8F2FAFE2AEDE.mlw
path: /opt/CAPEv2/storage/binaries/a868e4abe4ee49b4a1a9ca1cabe69a3e59a0560e83151c2608c2a564e5c0d309
crc32: 05AA2593
md5: 9cbc2acd8f2fafe2aedeafb77c6645fd
sha1: 3abb8ce995f306dd9f9f04b6a3c8bf625675bb34
sha256: a868e4abe4ee49b4a1a9ca1cabe69a3e59a0560e83151c2608c2a564e5c0d309
sha512: fd29f1fdf2049ccfda810b33e81f916461c12786aced1f10b54468bb4d31925594f24df767a589bd45ecc27f7d37f6a854fede359713beb92dda70673bfe2870
ssdeep: 192:zA1ckk3BTilzUPzkrwxYooDeMSRRL+SRR7JauVpEau1jVjaNuzW:zARMBOFJrwxYooDeiuVpbu1hPK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB52860667E44879F1FB463069AB5F7EEE77BC324A21951F42615A0F1C70F00BB11BA6
sha3_384: b7d100a42ccd99e3b017873d64c23a0935de082effbd7460e8345aaad569b46b221d7fbec8f7121e8fba8107c2e4ca32
ep_bytes: 9c60685374416c685468496ee8000000
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: AlcaTech
FileDescription: BPMPLAY.EXE
FileVersion: 4.9.0.0
InternalName: BPMPLAY
LegalCopyright: (c) 1995-2004 SwiftSoft
LegalTrademarks: (c) 1998-2004 AlcaTech
OriginalFilename: BPMPLAY.EXE
ProductName: BPM STUDIO
ProductVersion: 4.9.0.0
Comments:
ThinstallLicense: Internal development license
ThinstallVersion: 3.358
Translation: 0x0409 0x04e4

Backdoor.Generic.293659 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanBackdoor.Generic.293659
FireEyeBackdoor.Generic.293659
ALYacBackdoor.Generic.293659
CylanceUnsafe
ZillyaBackdoor.IRCBot.Win32.7973
AlibabaBackdoor:Win32/Generic.eb95cacf
CyrenW32/Backdoor.JUDH-3136
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PLA21
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderBackdoor.Generic.293659
NANO-AntivirusTrojan.Win32.Ot.olvpm
TencentWin32.Trojan.Spnr.Hxgm
Ad-AwareBackdoor.Generic.293659
TACHYONBackdoor/W32.IRCBot.13238
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Banbra.rh@4kvwju
VIPREBackdoor.IRCBot
TrendMicroTROJ_GEN.R002C0PLA21
McAfee-GW-EditionGeneric.dx!9CBC2ACD8F2F
EmsisoftBackdoor.Generic.293659 (B)
GDataBackdoor.Generic.293659
JiangminBackdoor/IRCBot.hsk
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGeneric.dx!9CBC2ACD8F2F
MAXmalware (ai score=81)
MaxSecureTrojan.Malware.2588.susgen
Cybereasonmalicious.d8f2fa
PandaTrj/CI.A

How to remove Backdoor.Generic.293659?

Backdoor.Generic.293659 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment