Backdoor

How to remove “Backdoor:MacOS/Vigorf.A”?

Malware Removal

The Backdoor:MacOS/Vigorf.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MacOS/Vigorf.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

Related domains:

infousa.xyz
apps.identrust.com

How to determine Backdoor:MacOS/Vigorf.A?


File Info:

crc32: 7D02B18A
md5: de74665eb2dd529284ecd219ce051c2d
name: DE74665EB2DD529284ECD219CE051C2D.mlw
sha1: 14b9bdbbbe0b54567497e4f00930214798b29511
sha256: 4c28a0848bf606b1fe5e705916e48916edfad5a6cdc9d82ee866b539b44991dc
sha512: 4f0fc6514e6f418687dc118e2245881a648a329aa400bf75efb75d0d0094095230b1ff7bdc63c6fd5c2ba9621f0ad142225178ebaecf8e7af78adc7496df3aa9
ssdeep: 192:qHNVR2LbOnb+VlJmEJhTAoy3Ha2sVjFXQ5n59EQyRCV4:+Jy73mEDTArKpVe8zCV4
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Backdoor:MacOS/Vigorf.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Generic.kYXw
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.GM.0040016022
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.77295
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Generic.14ed2468
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.eb2dd5
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyVHO:Backdoor.Win32.Androm.gen
BitDefenderGen:Trojan.Heur.GM.0040016022
MicroWorld-eScanGen:Trojan.Heur.GM.0040016022
TencentWin32.Trojan.Crypt.Wugy
Ad-AwareGen:Trojan.Heur.GM.0040016022
SophosML/PE-A
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
BitDefenderThetaAI:Packer.ADA959A81D
TrendMicroTROJ_GEN.R06CC0WF621
McAfee-GW-EditionBehavesLike.Win32.Generic.zh
FireEyeGeneric.mg.de74665eb2dd5292
EmsisoftGen:Trojan.Heur.GM.0040016022 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2AC7923
MicrosoftBackdoor:MacOS/Vigorf.A
GridinsoftTrojan.Heur!.030120E1
ArcabitTrojan.Heur.GM.D2629896
GDataGen:Trojan.Heur.GM.0040016022
Acronissuspicious
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=83)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.AI.1903992874
TrendMicro-HouseCallTROJ_GEN.R06CC0WF621
RisingTrojan.Generic@ML.100 (RDMK:Gfx0Y2v7rkUIArFuX/C8Pg)
IkarusTrojan.Crypt
MaxSecureVirus.Sality.AA
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxMBr0cA

How to remove Backdoor:MacOS/Vigorf.A?

Backdoor:MacOS/Vigorf.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment