Backdoor

What is “Backdoor.Win32.Poison.ggrf”?

Malware Removal

The Backdoor.Win32.Poison.ggrf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Poison.ggrf virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Poison.ggrf?


File Info:

crc32: 6D0E309E
md5: 842afc913a69de31c538ed7faa5d32de
name: chattt.exe
sha1: fe2f4190a0b8ee979aa8274a07a95d9f71797f65
sha256: 9ecba2f29729e227a4c55004474638eb85e30fd19e678d14e2ea3dbf3046f942
sha512: 70327b2194c03c26e951392394286224b68e307d8a27d878c17d3f4fe298236b5da677f6d08e561cb931e7fe6cc04d265bfd35c1464303dfd1e1f9e237b8f8b9
ssdeep: 6144:w0mlg+Q1BLpGH9G3L1JzBsDCnL0ucitxAvg9bTHTgT6HDxMW/NJQjlBhyVatD:ilQptLfBkCLTJtxA4b/g2DywrQ5YaJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Poison.ggrf also known as:

DrWebTrojan.MulDrop8.22787
MicroWorld-eScanTrojan.MSIL.Injector.MF
CMCBackdoor.Win32.Poison!O
CAT-QuickHealTrojanDropper.Small.PQ4
ALYacTrojan.MSIL.Injector.MF
MalwarebytesBackdoor.Dropper
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0040f2c01 )
K7AntiVirusTrojan ( 0040f2c01 )
ArcabitTrojan.MSIL.Injector.MF
Invinceaheuristic
BitDefenderThetaGen:Trojan.Heur2.PPBB.3.0.wqW@dO296Hiiq
F-ProtW32/GenTroj.S.gen!Eldorado
SymantecTrojan.Dropper!g1
ESET-NOD32Win32/TrojanDropper.Small.NMM
APEXMalicious
AvastWin32:GenMalicious-NUS [Trj]
ClamAVWin.Trojan.Poison-8692
KasperskyBackdoor.Win32.Poison.ggrf
BitDefenderTrojan.MSIL.Injector.MF
NANO-AntivirusTrojan.Win32.Poison.cbeljp
ViRobotBackdoor.Win32.Agent.67584.L
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
Ad-AwareTrojan.MSIL.Injector.MF
SophosTroj/Vbinder-D
ComodoTrojWare.Win32.Ransom.Xorist.ET@4mg4hg
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan-Dropper.Small.o
VIPREDetect.Trojan.Win32.Small.nmm (v)
TrendMicroTROJ_VBINDER.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.842afc913a69de31
EmsisoftTrojan.MSIL.Injector.MF (B)
SentinelOneDFI – Malicious PE
CyrenW32/GenTroj.S.gen!Eldorado
JiangminBackdoor/Poison.abtg
WebrootW32.Dropper.Gen
FortinetW32/Xorist.ET!tr
Antiy-AVLTrojan[Backdoor]/Win32.Poison
Endgamemalicious (high confidence)
MicrosoftVirTool:Win32/Vbinder
ZoneAlarmBackdoor.Win32.Poison.ggrf
AhnLab-V3Backdoor/Win32.Poison.R72119
Acronissuspicious
McAfeeGenericRXAC-LG!842AFC913A69
TACHYONBackdoor/W32.Poison.360960
VBA32Backdoor.Poison
CylanceUnsafe
PandaTrj/Injector.BH
TrendMicro-HouseCallTROJ_VBINDER.SM
RisingDropper.Win32.Small.bnv (CLASSIC)
YandexTrojan.Oxij.Gen.LA
GDataWin32.Trojan-Dropper.Agent.AMY
MaxSecureTrojan.Malware.6676023.susgen
AVGWin32:GenMalicious-NUS [Trj]
Cybereasonmalicious.13a69d
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Poison.B

How to remove Backdoor.Win32.Poison.ggrf?

Backdoor.Win32.Poison.ggrf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment