Backdoor Rootkit

About “Backdoor.Rootkit” infection

Malware Removal

The Backdoor.Rootkit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Rootkit virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor.Rootkit?


File Info:

name: AD9526D0E45723877483.mlw
path: /opt/CAPEv2/storage/binaries/356e967b75c4f6bfaf4b8df6dacebc9781a95cbe5cc312efd8ae336bca3dc08c
crc32: 68046286
md5: ad9526d0e457238774836a8cdd10e2b8
sha1: 10d5a37a8ef95c53f4e4c0846fe36914935dff8b
sha256: 356e967b75c4f6bfaf4b8df6dacebc9781a95cbe5cc312efd8ae336bca3dc08c
sha512: 8bb163f02b522267ea1b86f4b484f915383a8eef9bf1a387b68ad78d09530486db3576cb2aa5330b2ba40024368b92311f2dcec91a9f08824c2406455689807d
ssdeep: 24576:Z2V5DCU+BF1Q7ZV8Zofd/+7mwgpWJrPY9MUqCGCObn+3Zcgo+Iv4Z+q3C6C6IxGb:ZM5qSbC8cmw5JLfNB7C3o++4wq3POksI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10165F186A6D8C237E0A3C37488921249F2B45B511B38C7DB0397426DEF366FC9976367
sha3_384: 42141929cb8512dc5f65497da0b058e8afca9a36f12337bbb928c8ff9d1822295af4f7ab4f2150f59d99578b5b5d8ec9
ep_bytes: e83b190000e88318000033c0c3909090
timestamp: 2022-07-11 03:40:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Backdoor.Rootkit also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop20.20444
MicroWorld-eScanTrojan.GenericKD.39972926
FireEyeGeneric.mg.ad9526d0e4572387
CAT-QuickHealTrojan.Sabsik
McAfeeArtemis!AD9526D0E457
CylanceUnsafe
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusTrojan ( 005930da1 )
AlibabaTrojan:Win32/Blamon.2d24a57e
K7GWTrojan ( 005930da1 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/ABRisk.CGTP-7152
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tiggre-9845940-0
BitDefenderTrojan.GenericKD.39972926
AvastWin64:CrypterX-gen [Trj]
Ad-AwareTrojan.GenericKD.39972926
VIPRETrojan.GenericKD.39972926
TrendMicroTROJ_GEN.R002C0WGB22
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
AviraBDS/Backdoor.Gen3
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASCommon.218
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D261F03E
MicrosoftPUAAdvertising:Win32/LoadMoney
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Generic.R505562
VBA32Backdoor.Rootkit
ALYacTrojan.GenericKD.39972926
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:ScxJc5Zo5eeL4ecPH19FJA)
YandexTrojan.Blamon!yB1kWvgcN54
IkarusTrojan.Win32.Generic
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.BBYK!tr
AVGWin64:CrypterX-gen [Trj]

How to remove Backdoor.Rootkit?

Backdoor.Rootkit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment