Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

About “Backdoor:MSIL/AsyncRAT.ABE!MTB” infection

Published Apr 21, 2024 Backdoor category 3 min read
Report context

What to verify before removal

About “Backdoor:MSIL/AsyncRAT.ABE!MTB” infection deserves a credential-safety review because this backdoor label can overlap with remote access, browser data theft, or persistence after reboot. Cleanup should include scanning the file, removing the persistence point, and rotating exposed passwords from a clean device.

Start by comparing the local file name with 3126E6F6DBA59847029B.mlw, then review the behavior notes for credential theft, browser data access, remote-control activity, and persistence after reboot. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
3126E6F6DBA59847029B.mlw
  • Compare the suspicious file name with 3126E6F6DBA59847029B.mlw.
  • Confirm the detection name matches About “Backdoor:MSIL/AsyncRAT.ABE!MTB” infection before removing related files.
  • Review the report for credential theft, browser data access, remote-control activity, and persistence after reboot so the cleanup is based on observed behavior, not only the label.
  • After cleanup, rotate passwords from a clean device and review browser sessions or saved credentials.

The Backdoor:MSIL/AsyncRAT.ABE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Backdoor:MSIL/AsyncRAT.ABE!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/AsyncRAT.ABE!MTB?


File Info:

name: 3126E6F6DBA59847029B.mlw
path: /opt/CAPEv2/storage/binaries/94128f18eb9207acc05592414de54a9ef2a1feff4b1ad0ac9145305725498d0a
crc32: D7F8FB13
md5: 3126e6f6dba59847029bf5b3919ee63d
sha1: 69e9de7a4f00de9bde7adb9311d996976bc00d3c
sha256: 94128f18eb9207acc05592414de54a9ef2a1feff4b1ad0ac9145305725498d0a
sha512: f68197257cb4d676ea07240d146f59f0653efb05b0a80386a9de6471a6747b56b315ce5368378ed291164011b18bd03d799df41045f17911c9a5e245e60751be
ssdeep: 3072:sufi4N5YZYjzqzVz1zTRbE4g8OkZpY9UvrgNeZzO:ssXNuZYjzqzVz1zTRbE4g8OkZpY9UvrT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AB3C0127B8099EADEFC5A3634A9BECD58FDC08F4C954F8C224CDD7B3194742A91523A
sha3_384: fbdbb27a4243df491a65392849715e8ffb42110d99c3d617c1218d5a4d646d28e19f09f0792f13d7c8165395fb260192
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-05 17:11:16

Version Info:

Translation: 0x0000 0x04b0
FileDescription: 本流卡喬托的德喬金伴歐斯氏伴網喬闕拉莎桃普我蛋盟喬拉曲截普丁氏代拉拉金德爾伴弗的歐爾駛爾闕和本氏劇斯歐一盟盟流雙底加喇雙破蛋歐氏金德斯本氏德金閃內闕韋爾報明問德金氏歐底子斯報喇嗯馬伴雙腿斯子普閃斯底拉氏桃艾拉爾山的金闕閃曲進歐特明诶
FileVersion: 1.0.0.0
InternalName: terf.exe
LegalCopyright: Copyright © 2022
OriginalFilename: terf.exe
ProductName: 本流卡喬托的德喬金伴歐斯氏伴網喬闕拉莎桃普我蛋盟喬拉曲截普丁氏代拉拉金德爾伴弗的歐爾駛爾闕和本氏劇斯歐一盟盟流雙底加喇雙破蛋歐氏金德斯本氏德金閃內闕韋爾報明問德金氏歐底子斯報喇嗯馬伴雙腿斯子普閃斯底拉氏桃艾拉爾山的金闕閃曲進歐特明诶
ProductVersion: 1.0.0.0
Assembly Version: 0.0.0.0

Backdoor:MSIL/AsyncRAT.ABE!MTB also known as:

Bkav W32.AIDetectMalware.CS
AVG Win32:RATX-gen [Trj]
MicroWorld-eScan IL:Trojan.MSILMamut.8868
FireEye Generic.mg.3126e6f6dba59847
Skyhigh RDN/Generic BackDoor
ALYac IL:Trojan.MSILMamut.8868
Cylance unsafe
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Kryptik.ali2000016
K7GW Trojan ( 005972c91 )
K7AntiVirus Trojan ( 005972c91 )
BitDefenderTheta Gen:NN.ZemsilF.36802.hm0@aSSSPqp
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.GATX
APEX Malicious
Avast Win32:RATX-gen [Trj]
ClamAV Win.Dropper.Nanocore-10019966-0
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender IL:Trojan.MSILMamut.8868
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:nOSxHo4gKOfQ9htIoG23YQ)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.PackedNET.1540
VIPRE IL:Trojan.MSILMamut.8868
Emsisoft IL:Trojan.MSILMamut.8868 (B)
Ikarus Trojan.Dropper
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Trojan/MSIL.GenKryptik
Kingsoft malware.kb.c.999
Microsoft Backdoor:MSIL/AsyncRAT.ABE!MTB
Arcabit IL:Trojan.MSILMamut.D22A4
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
GData IL:Trojan.MSILMamut.8868
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5225644
McAfee RDN/Generic BackDoor
Malwarebytes Malware.AI.4142712698
MAX malware (ai score=89)
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/GenKryptik.FZAR!tr
DeepInstinct MALICIOUS

How to remove Backdoor:MSIL/AsyncRAT.ABE!MTB?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.