Backdoor

Backdoor.Generic.531651 malicious file

Malware Removal

The Backdoor.Generic.531651 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.531651 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Backdoor.Generic.531651?


File Info:

name: 9821AAFFC47471D23320.mlw
path: /opt/CAPEv2/storage/binaries/98106b707d9bc3df9f1e5991b639712bc078c67409dc22bfb18d449ff6678e7d
crc32: A1B09099
md5: 9821aaffc47471d233204da1f333be5d
sha1: 89746d0a658803df3ce0c7c352827e575a3cb7e6
sha256: 98106b707d9bc3df9f1e5991b639712bc078c67409dc22bfb18d449ff6678e7d
sha512: 555330c449551fc8b11a30bffc06615730a079d94fceee66bbe39b8f698abf07af0e1879ffdff100ed179d7b270e99e0fb72a0f48a4240dcfb36b292ee51a863
ssdeep: 24576:7xqT31T6WE6I5jKqosOm+bc8ZMsQFciRnkvxcN9V0hNGoOgbUWzZghKNwVpo0:G6WE6IN95+bc86sQC+nrN4zG7D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A455F22335E1A1B1C9A322F49F6BD369A779BC305631DB4B67D00E8E5730A51E736322
sha3_384: d58d2722fddf1b0d6990495f8ce1c853ece487f40edcbb02740eafe6bfe2423b4dd12043d33d2493667830586332dfe8
ep_bytes: e848b10000e917feffffb8ab094600a3
timestamp: 2008-06-12 08:51:05

Version Info:

FileDescription:
FileVersion: 3, 2, 12, 1
CompiledScript: AutoIt v3 Script : 3, 2, 12, 1
Translation: 0x0809 0x04b0

Backdoor.Generic.531651 also known as:

LionicTrojan.Win32.Genome.linK
MicroWorld-eScanBackdoor.Generic.531651
FireEyeGeneric.mg.9821aaffc47471d2
ALYacBackdoor.Generic.531651
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaAdWare:Win32/Swizzload.2817d74e
K7GWTrojan-Downloader ( 0055e3da1 )
BaiduNSIS.Trojan-Downloader.Agent.da
CyrenW32/S-2d34e4aa!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.FakeP2P.k
BitDefenderBackdoor.Generic.531651
NANO-AntivirusTrojan.Script.Autoit.debveb
AvastNSIS:Downloader-AT [Drp]
Ad-AwareBackdoor.Generic.531651
SophosWeemi (PUA)
ComodoMalware@#3blsdqiecvsoh
DrWebTrojan.StartPage.32993
VIPREC2.Lop
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
EmsisoftBackdoor.Generic.531651 (B)
GDataBackdoor.Generic.531651
JiangminTrojanClicker.AutoIt.kr
WebrootW32.Downloader.Swizzor.L
AviraTR/Dldr.Swizzor.L.179
Antiy-AVLTrojan/Generic.ASMalwNS.6
KingsoftWin32.Troj.Generic.(kcloud)
ArcabitBackdoor.Generic.D81CC3
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!9821AAFFC474
MAXmalware (ai score=83)
VBA32Adware.FakeP2P
MalwarebytesMalware.AI.2653908659
TrendMicro-HouseCallTROJ_GEN.R002H0CL221
TencentWin32.Adware.Fakep2p.Hsib
FortinetRiskware/PUP_z
BitDefenderThetaAI:Packer.2F74BAB617
AVGNSIS:Downloader-AT [Drp]
PandaTrj/CI.A
MaxSecureTrojan.Malware.4953821.susgen

How to remove Backdoor.Generic.531651?

Backdoor.Generic.531651 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment