Backdoor

About “Backdoor.Win32.Agent.pef” infection

Malware Removal

The Backdoor.Win32.Agent.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Agent.pef virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Agent.pef?


File Info:

crc32: 9E4AE3C3
md5: 6013611a39183c9960700b47eff92a56
name: 6013611A39183C9960700B47EFF92A56.mlw
sha1: 6a0dfd4e5d1e8a9b47bccdd9f508112c4606e777
sha256: 02d0b0065d46263a124b65dfa66324fb0e6b4a841fe9b7ac23fa7dd6e1973e8e
sha512: 03a7b41f8b9863e4fab9cab5aef9e3024d2de58a5b0afa5e84b50a7875473aff7e8d3874a365e06cf0f844505929ddd34a403fefcbdad17ae40364d1a914e2a5
ssdeep: 24576:g9pLaPkSyxNbdTBsMrx8N99ELHLeB/2yEZpbQlVx+4HqrFIStTJSjG8h:g75SAHGWSN9cLrHmlrZ3StIjG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 13.54.17.21
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0184 0x046a

Backdoor.Win32.Agent.pef also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Packed.Generic-9908949-0
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWHacktool ( 700007861 )
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Agent.pef
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34266.Vr0@aCyhj0cO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.6013611a39183c99
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
McAfeeArtemis!6013611A3918
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazqOmgogyzV+dE8J8cw36jMS)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.Agent.pef?

Backdoor.Win32.Agent.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment