Backdoor

Backdoor.SlimRat removal guide

Malware Removal

The Backdoor.SlimRat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.SlimRat virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.daiman.nl

How to determine Backdoor.SlimRat?


File Info:

crc32: A8BEC723
md5: 9fd436d3e2d933e96eabea38e0c5aca6
name: avira_av.exe
sha1: e9f26cfb96a23da3305f7c7626eae8b6f76cf5fc
sha256: a1e0799365123c203abda5e44e6687d14f7bee6aac13495442ac0ef72f9fc99b
sha512: 5900107d429df9df65242a46ea0179b415b3b079c5e8e181c3997b9175ee664810c69aaa980175807c20a99b1db3db6360708ebfef028550aa582c5808cdd31b
ssdeep: 3072:m9RxgFm76kbaruF1PcEm4cjBS77I0T4UJ2jGZcorc:qHyWcE1q477I0T4UJ2jGZX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: avira_av
FileVersion: 1.00
CompanyName: BKHN
ProductName: Project1
ProductVersion: 1.00
OriginalFilename: avira_av.exe

Backdoor.SlimRat also known as:

MicroWorld-eScanGeneric.Malware.SFP!V!A!Tk.32DB2068
FireEyeGeneric.mg.9fd436d3e2d933e9
CAT-QuickHealTrojanRansom.Blocker
McAfeeRDN/Generic BackDoor
MalwarebytesBackdoor.SlimRat
VIPREBackdoor.Win32.Retig.de (v)
SangforMalware
K7AntiVirusTrojan ( 005173c61 )
BitDefenderGeneric.Malware.SFP!V!A!Tk.32DB2068
K7GWTrojan ( 005173c61 )
Cybereasonmalicious.3e2d93
TrendMicroRansom_Blocker.R035C0PKN19
BitDefenderThetaAI:Packer.B94DFC8D1F
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallRansom_Blocker.R035C0PKN19
AvastWin32:Trojan-gen
ClamAVWin.Trojan.VB-989
GDataGeneric.Malware.SFP!V!A!Tk.32DB2068
KasperskyTrojan-Ransom.Win32.Blocker.mfam
AlibabaBackdoor:Win32/Generic.ed65ba71
NANO-AntivirusTrojan.Win32.Ric.gixrmd
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Generic!8.C3 (TFE:5:A8wpwXNVdzO)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Gen
DrWebBACKDOOR.Trojan
McAfee-GW-EditionRDN/Generic BackDoor
SentinelOneDFI – Malicious PE
EmsisoftGeneric.Malware.SFP!V!A!Tk.32DB2068 (B)
AviraTR/Spy.Gen
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitGeneric.Malware.SFP!V!A!Tk.32DB2068
ZoneAlarmTrojan-Ransom.Win32.Blocker.mfam
AhnLab-V3Trojan/Win32.Blocker.R302842
ALYacGeneric.Malware.SFP!V!A!Tk.32DB2068
MAXmalware (ai score=82)
Ad-AwareGeneric.Malware.SFP!V!A!Tk.32DB2068
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of NewHeur_VB_Backdoor.4
IkarusBackdoor.Win32.RShot
FortinetW32/Blocker.MFAM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Ransom.52b

How to remove Backdoor.SlimRat?

Backdoor.SlimRat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment