Backdoor

What is “Backdoor.Win32.Poison.aec”?

Malware Removal

The Backdoor.Win32.Poison.aec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Poison.aec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the PoisonIvy malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Win32.Poison.aec?


File Info:

name: 9DAACB39D0C7EF5D7D55.mlw
path: /opt/CAPEv2/storage/binaries/b05699dbb0e0b9b8d388270844f0572604cb42a876e599badff120fe25dd7329
crc32: A4464CF2
md5: 9daacb39d0c7ef5d7d559d3a6412e8e7
sha1: 256060c63b437d051cff5d33c197a97203383369
sha256: b05699dbb0e0b9b8d388270844f0572604cb42a876e599badff120fe25dd7329
sha512: 187befb4413531ab03e6111b39918d9be7e544b7b5ec2b793dc24a94c3fac2c3d5de2c4d7ed62a5e0db91c97d1d2ebbe289f459eee0c0ca80e729147ae51a95b
ssdeep: 6144:rRITJbuV/JDntV1qATxxBdFwYUnDARdt8mfZRzzX:O6hDtnquXWnotfHX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA541255FB808893F4B4957018765F29F3725D57A432691F27F07EA2DAF20828B214BF
sha3_384: 00ca38a0e2c915bd70b0cdf6069bf3b39ac46b3aed6676991b521be5b6f1d2ef549bab0fc73ccf886a04e71b6b37588b
ep_bytes: 558bec81ec80010000535633db57895d
timestamp: 2007-03-31 15:09:55

Version Info:

0: [No Data]

Backdoor.Win32.Poison.aec also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Poison.m!c
MicroWorld-eScanTrojan.Downloader.Agent.ZCR
FireEyeGeneric.mg.9daacb39d0c7ef5d
CAT-QuickHealTrojanAPT.Poisonivy.D3
ALYacTrojan.Downloader.Agent.ZCR
MalwarebytesMalware.AI.3326531363
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 00199f611 )
BitDefenderTrojan.Downloader.Agent.ZCR
K7GWTrojan ( 005325ee1 )
Cybereasonmalicious.9d0c7e
ArcabitTrojan.Downloader.Agent.ZCR
BaiduWin32.Backdoor.Poison.a
VirITBackdoor.Win32.Poison.D
CyrenW32/Injector.BE.gen!Eldorado
SymantecBackdoor.Darkmoon
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Trojan.Inject-3579
KasperskyBackdoor.Win32.Poison.aec
AlibabaBackdoor:Win32/Poison.a1c7f236
NANO-AntivirusTrojan.Win32.Poison.tlvcr
RisingBackdoor.Poison!1.A046 (CLASSIC:BxjvtZaPEwQCVnlC2GoFDA)
SophosMal/Behav-043
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebBackDoor.Poison.686
VIPRETrojan.Downloader.Agent.ZCR
TrendMicroBKDR_POISON.DS
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftTrojan.Downloader.Agent.ZCR (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/PoisonIvy.jh
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Poison
XcitiumMalware@#1kl86mnol5j62
MicrosoftBackdoor:Win32/Poison.CD
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Downloader.Agent.ZCR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Poison.R2018
Acronissuspicious
McAfeeArtemis!9DAACB39D0C7
DeepInstinctMALICIOUS
VBA32Backdoor.Bifrose
Cylanceunsafe
PandaTrj/CI.A
ZonerTrojan.Win32.29989
TrendMicro-HouseCallBKDR_POISON.DS
TencentWin32.Backdoor.Agent.Yolw
YandexTrojan.GenAsa!hoaG+ClzUzQ
IkarusTrojan.Win32.Inject
FortinetW32/Poison.CWKQ!tr.bdr
BitDefenderThetaAI:Packer.F705ECD61F
AVGWin32:Agent-AAGI [Trj]
AvastWin32:Agent-AAGI [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Backdoor.Win32.Poison.aec?

Backdoor.Win32.Poison.aec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment