Categories: Backdoor

Backdoor.RAT.Parallax malicious file

The Backdoor.RAT.Parallax is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.RAT.Parallax virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.RAT.Parallax?


File Info:

crc32: 8DC5FD97md5: 823be1cd7defa02113ad36530c55b278name: 823BE1CD7DEFA02113AD36530C55B278.mlwsha1: e55ef9e7834fc9371e02fa4bdeb699d1f8819eadsha256: e6e9b8fe2bb57d5dc22953b423d6340ef3adf9ebef4852a842c9c87e9d3fead7sha512: 997b18aaa326ebaa0de683bd590f704abdbb8d1d8f24cef263723f3211b6f464b60b2266cb3767fa6852870fc4e54611eb1a646c28b24466d3e6ef7ab6be80c5ssdeep: 49152:CxZmYC4csZ7gzH3h42+pt1hwOHUqB8ZrkWtKy1lNHnFeX2y4ssKbs8wSIlTAY:CbmYCwOTy2+L1iO0GlWtKy1lNHnFeX2Vtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1999-2017 Famatech Corp. and its licensors. All rights reserved.InternalName: RadminFileVersion: 3, 5, 2, 0CompanyName: Famatech Corp.PrivateBuild: LegalTrademarks: Radmin, Remote AdministratorComments: Radmin ViewerProductName: Radmin ViewerSpecialBuild: ProductVersion: 3, 5, 2, 0FileDescription: Radmin ViewerOriginalFilename: Radmin.exeTranslation: 0x0409 0x04b0

Backdoor.RAT.Parallax also known as:

MicroWorld-eScan Gen:Variant.Razy.605759
McAfee Artemis!823BE1CD7DEF
Cylance Unsafe
K7AntiVirus Trojan ( 00577ff51 )
BitDefender Gen:Variant.Razy.605759
K7GW Trojan ( 00577ff51 )
Cybereason malicious.d7defa
Cyren W32/Trojan.WENR-6623
Symantec Trojan.Gen.MBT
Avast Win32:DangerousSig [Trj]
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/GenCBL.eab93604
Rising Trojan.GenCBL!8.12138 (CLOUD)
Ad-Aware Gen:Variant.Razy.605759
Emsisoft MalCert.A (A)
Comodo Malware@#32av8o4mfnv9h
F-Secure Trojan.TR/AD.ParallaxRat.cupjv
DrWeb BackDoor.Rat.324
TrendMicro TROJ_FRS.VSNTBI21
McAfee-GW-Edition Artemis!Trojan
FireEye Gen:Variant.Razy.605759
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Gencbl
Avira TR/AD.ParallaxRat.cupjv
MAX malware (ai score=84)
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Microsoft Trojan:Win32/Ymacco.AAE6
Arcabit Trojan.Razy.D93E3F
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Gen:Variant.Razy.605759
Cynet Malicious (score: 85)
AhnLab-V3 Malware/Gen.Reputation.C4340367
ALYac Backdoor.RAT.Parallax
Malwarebytes Generic.Malware/Suspicious
ESET-NOD32 a variant of Win32/GenCBL.YQ
TrendMicro-HouseCall TROJ_FRS.VSNTBI21
Fortinet W32/GenCBL.YQ!tr
AVG Win32:DangerousSig [Trj]
Paloalto generic.ml
Qihoo-360 Win32/Trojan.Generic.HgIASPMA

How to remove Backdoor.RAT.Parallax?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Troj/VB-IGX”?

The Troj/VB-IGX is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago

UDS:Trojan.Win32.DBadur removal tips

The UDS:Trojan.Win32.DBadur is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

What is “Jalapeno.348”?

The Jalapeno.348 is considered dangerous by lots of security experts. When this infection is active,…

43 mins ago

Razy.665944 removal

The Razy.665944 is considered dangerous by lots of security experts. When this infection is active,…

53 mins ago

Symmi.3599 removal instruction

The Symmi.3599 is considered dangerous by lots of security experts. When this infection is active,…

54 mins ago

Malware.AI.73035705 information

The Malware.AI.73035705 is considered dangerous by lots of security experts. When this infection is active,…

55 mins ago