Backdoor

Backdoor.Kocega removal instruction

Malware Removal

The Backdoor.Kocega is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Kocega virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Kocega?


File Info:

name: ECE365569AAEDE589A00.mlw
path: /opt/CAPEv2/storage/binaries/fd4bdb3903c74830f0fc178b217ea6df72adc19e8f35ab23372a582dbf521e64
crc32: 35CD5287
md5: ece365569aaede589a005c41462d5e84
sha1: e5af5f75a050fd21e27269fb3a6b9705e73dfe14
sha256: fd4bdb3903c74830f0fc178b217ea6df72adc19e8f35ab23372a582dbf521e64
sha512: 347ccdd478207cae8dbb8f9363bda5ffcde4b10e6581c33bf9c7797ff955b4f2e07a8ae19d02d706d9f0cae89d5c188cb5b5d9c5f983c7e097d9856c40c9a1a5
ssdeep: 384:N3/Z9MwtIzNT/Xcf2+Te7azw5/aLGaXwlaAkWOvpzVZ1cY1:J/Z9MwtIzNT/XcRnzw59eWO5ziC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B763290EB65299B1C6E905F22B36040FABBEFC6005DAEB06EA93038E5971DC7D53134D
sha3_384: dfdc9d7740218ad3247e9358c1db4502f040abe0f972e36757e0510ae7e2e3cb5faf1ef2dd939600038330877c3a08e7
ep_bytes: 00000000000000000000000000000000
timestamp: 2008-03-14 09:32:14

Version Info:

0: [No Data]

Backdoor.Kocega also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.Pace
MicroWorld-eScanTrojan.GenericKDZ.99328
ClamAVWin.Worm.Socks-9
FireEyeGeneric.mg.ece365569aaede58
CAT-QuickHealBackdoor.Kocega
ALYacTrojan.GenericKDZ.99328
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Koceg.b81422a9
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5a050f
CyrenW32/Heuristic-CO3!Eldorado
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.99328
SUPERAntiSpywareTrojan.Unclassified/Spools-Fake
AvastWin32:Small-KCA [Trj]
TencentWin32.Trojan.Generic.Agow
EmsisoftTrojan.GenericKDZ.99328 (B)
F-SecureTrojan.TR/Dldr.Agent.agl
BaiduWin32.Trojan-Downloader.Agent.au
VIPRETrojan.GenericKDZ.99328
TrendMicroTROJ_GEN.R03BC0DF823
McAfee-GW-EditionBehavesLike.Win32.Generic.kz
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Trojan.PSE.1O73J62
AviraTR/Dldr.Agent.agl
Antiy-AVLTrojan[Backdoor]/Win32.Koceg
XcitiumTrojWare.Win32.Kryptik.ATA@4na219
ArcabitTrojan.Generic.D18400
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Koceg.gen!A
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C3062327
McAfeeArtemis!ECE365569AAE
MAXmalware (ai score=82)
MalwarebytesMalware.AI.1178115061
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DF823
RisingTrojan.Generic@AI.100 (RDML:dB+5ru2xj4vCWYBEj+gNMw)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Mabezat.Dam
FortinetW32/GenericKDZ.99328!tr
AVGWin32:Small-KCA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Kocega?

Backdoor.Kocega removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment