Backdoor

Backdoor.Generic.792814 malicious file

Malware Removal

The Backdoor.Generic.792814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.792814 virus can do?

  • Attempts to connect to a dead IP:Port (36 unique times)
  • Starts servers listening on 0.0.0.0:41826
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Creates an autorun.inf file
  • Sniffs keystrokes
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Generates some ICMP traffic

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyip.everdot.org
www.whatismyip.com
www.showmyipaddress.com
whatismyipaddress.com
www.whatismyip.ca
www.facebook.com
fydarnfoduz.com
msycseqecs.com
jhwxluen.info
agjtrjto.net
fwcddz.net
rabrurfdwl.info
lsjzninttist.info
luarnfp.net
iwgkociqow.com
sscoagscsu.com
dzjjpasm.net
jpkhsubydbyj.net
ogoees.org
uuqmkcyk.com
ofxeqzbrxin.net
cdzznrnzbypj.net
jmrfkuu.info
syonvysd.info
rwesmqvem.net
fsusrxar.net
uamkoguomgma.org
ctgliqxunb.info
furskys.org
kjrcyhqc.info
uutlwwi.info
wsxtxbhtatx.net
bblghnuibel.net
nsdpkmcdvt.info
fqpcqphdya.info
wsjoscjnzaf.net
xnukel.net
groqrdl.net
ratsoobut.com
sqqiel.info
oqjxswvenxr.net
jzgjkc.info
sqncgskjbab.info
heqhgkaxppyg.net
agicsk.com
drrlfqizrxog.info
tcegpkql.net
ifhfof.info
ujfbpflbfbi.info
iigorit.net
nktsbjzktjvb.net
fgflshbfjw.info
dfjcgmtox.com
hfvycklnidfe.net
vzjflerclv.info
navgxyton.info
kibxxvjlb.net
rzfbki.net
tuiljntvpb.net
xiypmgzzua.info

How to determine Backdoor.Generic.792814?


File Info:

crc32: 86C70E9F
md5: 1a9de018bb9b4d6a3eba0fe967608172
name: 1A9DE018BB9B4D6A3EBA0FE967608172.mlw
sha1: 1898c6eec469fe552f1be5ca63cb4417c12b3cb0
sha256: 3ad971d2c93140165c588098ad98f520ae6dff21ad3576eccc9056ba783d38b1
sha512: 641ce1454e67928d41996e324c2db6af2490fa39209d8cd2571342184b30fac82bd4a64745c3a4f6789f0f327357c8c7c18ff2d94c8cc45c728790228dfa8b7b
ssdeep: 12288:ApUJ3r6YkVwJgNnSykgb9cqWnw4q6ZmFhqs/rlu:ApUNr6YkVRFkgbeqeo68FhqyrM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Generic.792814 also known as:

BkavW32.ZeaorwsgjokXB.Trojan
K7AntiVirusBackdoor ( 002ddfdb1 )
Elasticmalicious (high confidence)
DrWebTrojan.KillAV.47
CynetMalicious (score: 100)
CAT-QuickHealTrojan.KillAv.DR
ALYacBackdoor.Generic.792814
CylanceUnsafe
ZillyaTrojan.AntiAV.Win32.2243
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Zepfod.0f73fc93
K7GWBackdoor ( 002ddfdb1 )
Cybereasonmalicious.8bb9b4
TrendMicroBKDR_KILLAV.SM
BaiduWin32.Backdoor.Agent.q
CyrenW32/Backdoor.CLWD-5549
SymantecBackdoor.Trojan
ESET-NOD32Win32/AutoRun.Agent.UD
ZonerTrojan.Win32.54103
APEXMalicious
AvastWin32:GenMalicious-BJV [Trj]
ClamAVWin.Trojan.Zepfod-6747518-0
KasperskyBackdoor.Win32.Zepfod.yy
BitDefenderBackdoor.Generic.792814
NANO-AntivirusTrojan.Win32.Zepfod.bdqfn
ViRobotTrojan.Win32.AntiAV.577536
SUPERAntiSpywareTrojan.Agent/Gen-AntiAV
MicroWorld-eScanBackdoor.Generic.792814
TencentBackdoor.Win32.Zepfod.aaa
Ad-AwareBackdoor.Generic.792814
SophosTroj/Bckdr-RAJ
ComodoTrojWare.Win32.Scar.GF@1s6ub7
F-SecureTrojan.TR/Zugy.iks.1
BitDefenderThetaAI:Packer.0F84B57A1F
VIPREWorm.Win32.Pykspa (v)
InvinceaML/PE-A + Troj/Bckdr-RAJ
McAfee-GW-EditionBehavesLike.Win32.Sality.fh
FireEyeGeneric.mg.1a9de018bb9b4d6a
EmsisoftBackdoor.Generic.792814 (B)
SentinelOneDFI – Malicious PE
JiangminBackdoor/Zepfod.e
WebrootW32.Sality.Gen
AviraTR/Zugy.iks.1
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Backdoor]/Win32.Zepfod
MicrosoftTrojan:Win32/Killav.DR
ArcabitBackdoor.Generic.DC18EE
AegisLabTrojan.Win32.Zepfod.lAtB
ZoneAlarmBackdoor.Win32.Zepfod.yy
GDataBackdoor.Generic.792814
AhnLab-V3Win-Trojan/Killav.577536.G
Acronissuspicious
McAfeeBackDoor-EJG
MAXmalware (ai score=100)
MalwarebytesTrojan.KillAV
PandaW32/SpySkype.E
TrendMicro-HouseCallBKDR_KILLAV.SM
RisingHackTool.Obfuscator!1.65F9 (CLASSIC)
YandexBackdoor.Zepfod!WVKWmMMJuzs
IkarusTrojan.Win32.KillAV
MaxSecureBackdoor.Zepfod.yy
FortinetW32/Generic.AC.5027!tr
AVGWin32:GenMalicious-BJV [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.e18

How to remove Backdoor.Generic.792814?

Backdoor.Generic.792814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment