Backdoor Worm

Should I remove “Backdoor.LimeWorm”?

Malware Removal

The Backdoor.LimeWorm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.LimeWorm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Detects VMware through the presence of a file
  • Anomalous binary characteristics

How to determine Backdoor.LimeWorm?


File Info:

crc32: 8E61F0F2
md5: 046e185bd5ec30898eff334586965e40
name: 046E185BD5EC30898EFF334586965E40.mlw
sha1: 9f3fb83bb8964f17e3718e4730e7c24f25ce8b9c
sha256: 906ecbec32e9c137e95af0ff18ed1aabcb6863837b864292b8f245d3a4794e9d
sha512: 4e833b9e69e17372ca2f64eea51fb25ba5472ca5acd75533116fbd9f435e281aa31fca69e223a7edac76991fd1bb9ad0a3d96ba8b2998a272e02cb84c6189792
ssdeep: 384:MzZ55Hd4x1Oe+sgJda+Jf7h7ARN2dIMKm+EpU5HPMwQro3owEL:5aB97oz0aUL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.5.8.0
InternalName: Stub.exe
FileVersion: 0.5.8.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 0.5.8.0
FileDescription:
OriginalFilename: Stub.exe

Backdoor.LimeWorm also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.23055
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GeneFC.S17875539
ALYacIL:Trojan.MSILZilla.7623
CylanceUnsafe
ZillyaDropper.Generic.Win32.13683
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.bd5ec3
CyrenW32/Trojan.SW.gen!Eldorado
ESET-NOD32a variant of MSIL/Agent.SMX
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.LimeRAT-7722829-0
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.7623
MicroWorld-eScanIL:Trojan.MSILZilla.7623
Ad-AwareIL:Trojan.MSILZilla.7623
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34266.bm0@aOj7H5k
McAfee-GW-EditionGenericRXGA-SC!046E185BD5EC
FireEyeGeneric.mg.046e185bd5ec3089
EmsisoftIL:Trojan.MSILZilla.7623 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Generic.cyg
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.309680E
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitIL:Trojan.MSILZilla.D1DC7
SUPERAntiSpywareTrojan.Agent/Gen-MSILPerseus
GDataIL:Trojan.MSILZilla.7623
AhnLab-V3Malware/RL.Generic.R255652
McAfeeGenericRXGA-SC!046E185BD5EC
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.LimeWorm
PandaTrj/GdSda.A
YandexTrojan.Agent!SiXHiacY4vg
IkarusTrojan-Dropper.Win32.Dorifel
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.SMX!tr
AVGWin32:DropperX-gen [Drp]

How to remove Backdoor.LimeWorm?

Backdoor.LimeWorm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment