Backdoor

Backdoor.MSIL.Horus (file analysis)

Malware Removal

The Backdoor.MSIL.Horus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Horus virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.MSIL.Horus?


File Info:

crc32: 9540942C
md5: 1e2b7728f6db35af799760a123542fee
name: 1E2B7728F6DB35AF799760A123542FEE.mlw
sha1: c43a77b06cb7ac60b657cd0b9de930c3d92081f5
sha256: e8ef46e417bedaa21c478313cd8f007eb81a8f7099b796d62a61d67b95974302
sha512: f5c101d4195293c5d9f6f386266e48b092e4b038ccf52ca9e6114429d4c324dcacdc321240c9f583f570be1464c4086695284ed084e8af080f676bd0c48c5f8f
ssdeep: 384:7hmEOXbEyhb1PzZXm+oRyVl/D6lyVuXHOpArj/XQqneLZbU8VYrVWe9kSR9tr61:lmvrEyVXqRsruyAXusjBE1VxGUE2o
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Stub.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Stub.exe

Backdoor.MSIL.Horus also known as:

BkavW32.ZpevJaikIA.Trojan
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.WacatacFC.S18895185
ALYacGen:Heur.MSIL.Krypt.2
CylanceUnsafe
ZillyaTrojan.GenericML.Win32.199
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:MSIL/Horus.53b61053
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8f6db3
CyrenW32/Trojan.PFBR-6482
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DDO
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Backdoor.MSIL.Horus.gen
BitDefenderGen:Heur.MSIL.Krypt.2
NANO-AntivirusTrojan.Win32.Horus.iwkdhz
MicroWorld-eScanGen:Heur.MSIL.Krypt.2
TencentMsil.Backdoor.Horus.Dzap
Ad-AwareGen:Heur.MSIL.Krypt.2
SophosMal/Generic-S
ComodoMalware@#3h45v4wdjhjly
BitDefenderThetaGen:NN.ZemsilF.34058.bm0@ayeYCBi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic Dropper
FireEyeGeneric.mg.1e2b7728f6db35af
EmsisoftGen:Heur.MSIL.Krypt.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.erpc
WebrootW32.Dropper.Gen
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_73%
Antiy-AVLTrojan/Generic.ASMalwS.3134D0F
MicrosoftTrojan:Win32/Ymacco.AAE8
ArcabitTrojan.MSIL.Krypt.2
GDataGen:Heur.MSIL.Krypt.2
AhnLab-V3Malware/Win32.RL_Generic.R278387
McAfeeRDN/Generic Dropper
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack
YandexTrojan.DR.Agent!mR5jPBURl14
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.114771601.susgen
FortinetPossibleThreat
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwMAu1sA

How to remove Backdoor.MSIL.Horus?

Backdoor.MSIL.Horus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment