Backdoor

Backdoor.Win32.Raroger.ne removal guide

Malware Removal

The Backdoor.Win32.Raroger.ne is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Raroger.ne virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Attempts to make use of the Filter Manager
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Checks the system manufacturer, likely for anti-virtualization
  • Clears Windows events or logs
  • Accessed credential storage files
  • Accessed credential storage registry keys
  • Deletes executed files from disk
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor.Win32.Raroger.ne?


File Info:

name: A95BC861094EEBB3C142.mlw
path: /opt/CAPEv2/storage/binaries/eaa7bc938990e76081dc2b421e57216522e209dda6b80e990490ba19e3527510
crc32: 1B6E4744
md5: a95bc861094eebb3c142be352019bf41
sha1: 32b98d2e77159975e6dacf2ed2aecb36dc6a955c
sha256: eaa7bc938990e76081dc2b421e57216522e209dda6b80e990490ba19e3527510
sha512: 746320d60991f7759cde63e19b5e0bc0f7c387a846fcb050df60d10bb4a27af141a536a5e7193c9b7d791ee7f6024072ee58c0b7e9badb90ade118291188a7b1
ssdeep: 196608:3Yt2fWPjfamNAEvo4OYrelqi/46228nwFTziq8ZGvGLdVVG8BgvdJFF7PdpQ8DGd:3YIijBNAayyuq/dYeq8QGE9XPdpQKGL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152D6334217809299D9B820FCCCF855D82D9ED17FC3018F653B08E87D7B315A9EB25B9A
sha3_384: 4666cec276dfc5f5f981e29c7acb7710a46f7aac0643fe6e2682b1e450fad5f6cd087c78fef98e627e4a5555949e35f3
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:43

Version Info:

Comments: WhySoSlow Home Edition Setup
CompanyName: Resplendence Software Projects Sp.
FileDescription: WhySoSlow Home Edition Setup
FileVersion: 0.0.0.0
LegalCopyright:
OriginalFilename: WhySoSlowSetup.exe
ProductName: WhySoSlow Home Edition
ProductVersion:
Translation: 0x0409 0x04b0

Backdoor.Win32.Raroger.ne also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Raroger.m!c
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Porcupine.@x3@bidGjDdig
FireEyeGen:Heur.Mint.Porcupine.@x3@bidGjDdig
CAT-QuickHealTrojan.CoinMiner.S30516202
SkyhighBehavesLike.Win32.Generic.rc
McAfeeArtemis!A95BC861094E
Cylanceunsafe
ZillyaTrojan.Fsysna.Win32.64167
SangforBackdoor.Win32.Raroger.V13a
K7AntiVirusTrojan ( 005aa1bb1 )
AlibabaBackdoor:Win32/Raroger.36745c45
K7GWTrojan ( 005aa1bb1 )
Cybereasonmalicious.1094ee
ArcabitTrojan.Mint.Porcupine.EED23BE
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
CynetMalicious (score: 100)
APEXMalicious
KasperskyBackdoor.Win32.Raroger.ne
BitDefenderGen:Heur.Mint.Porcupine.@x3@bidGjDdig
NANO-AntivirusTrojan.Win32.Mint.kdicmu
AvastWin32:Evo-gen [Trj]
TencentVbs.Trojan.Alien.Bwnw
EmsisoftGen:Heur.Mint.Porcupine.@x3@bidGjDdig (B)
F-SecureHeuristic.HEUR/AGEN.1366393
DrWebTrojan.Siggen22.1424
VIPREGen:Heur.Mint.Porcupine.@x3@bidGjDdig
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win64.Krypt
VaristW32/Agent.GOA.gen!Eldorado
AviraTR/Kryptik.hcloz
Antiy-AVLTrojan/Win64.GenKryptik
MicrosoftTrojan:Win32/CoinMiner.QT!bit
ZoneAlarmHEUR:Trojan.VBS.Alien.gen
GDataGen:Heur.Mint.Porcupine.@x3@bidGjDdig
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5443850
Acronissuspicious
VBA32BScope.TrojanBanker.Mekoban
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingTrojan.HiddenRun/NSIS!1.E740 (CLASSIC)
YandexRiskware.VMProtect!5EDW7cSPvgQ
FortinetW32/Malicious_Behavior.SBX
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Raroger.ne?

Backdoor.Win32.Raroger.ne removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment