Backdoor

Backdoor.Poison.XorGen removal

Malware Removal

The Backdoor.Poison.XorGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Poison.XorGen virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Poison.XorGen?


File Info:

crc32: EE0F00CE
md5: 2569898c4a735ae6f056b2cbf9dd0c47
name: 2569898C4A735AE6F056B2CBF9DD0C47.mlw
sha1: 9e4e17f30f1acc1d0a2e78cfe278fbf6672a5aa7
sha256: 06f90298156769d7d36397266ebed17d40623b6fbee75a4a9c580f94523b0996
sha512: d86919acd6c4d81a644eada46077d5d514b00661fb1f974331ced798d9be87aa95a8b203b61221c1e240860b113701979bea66b3edd848cd687b05681468c9be
ssdeep: 196608:PAv5TstCRhS5RW52osuhGi5U7MlrWHOdW57t9gf0UB8yZiRPowGMZa8I:4vat+I5g5llv3I2W50ftiyYFowVa8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Poison.XorGen also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EPAA
Qihoo-360HEUR/QVM20.1.455B.Malware.Gen
McAfeeDownloader-FYE!2569898C4A73
CylanceUnsafe
VIPREDetect.Trojan.Win32.Small.nmm (v)
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Agent.EPAA
K7GWTrojan ( 0040f2c01 )
K7AntiVirusTrojan ( 0040f2c01 )
BitDefenderThetaGen:NN.ZexaF.34634.@tW@aWv9RZoi
CyrenW32/GenTroj.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Agent-1346944
KasperskyTrojan.Win32.Agent.hwgs
RisingTrojan.Neshta!1.993B (CLASSIC)
Ad-AwareTrojan.Agent.EPAA
EmsisoftTrojan.Agent.EPAA (B)
F-SecureTrojan:W32/Ransom.AE
DrWebTrojan.DownLoader5.51735
ZillyaTrojan.Agent.Win32.1517682
InvinceaTroj/Small-EUW
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.2569898c4a735ae6
SophosTroj/Small-EUW
IkarusVirus.Win32.Heur
JiangminTrojan/Neshta.a
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Dorv.A!rfn
ArcabitTrojan.Agent.EPAA
ZoneAlarmTrojan.Win32.Agent.hwgs
GDataWin32.Trojan-Dropper.Agent.AMY
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fynloski.R23047
Acronissuspicious
VBA32BScope.Backdoor.Poison
ALYacTrojan.Agent.EPAA
MAXmalware (ai score=89)
MalwarebytesBackdoor.Poison.XorGen
PandaGeneric Malware
ESET-NOD32a variant of Win32/TrojanDropper.Small.NMM
YandexTrojan.GenAsa!T8P/UkYT/k8
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Xorist.ET!tr
AVGWin32:Ransom-NB [Trj]
Cybereasonmalicious.c4a735
AvastWin32:Ransom-NB [Trj]
MaxSecureVirus.W32.Neshta.A

How to remove Backdoor.Poison.XorGen?

Backdoor.Poison.XorGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment