Backdoor

Backdoor:MSIL/AsyncRAT!MSR removal

Malware Removal

The Backdoor:MSIL/AsyncRAT!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/AsyncRAT!MSR virus can do?

  • Network activity detected but not expressed in API logs

How to determine Backdoor:MSIL/AsyncRAT!MSR?


File Info:

crc32: A1FFAA37
md5: 6d27ac6f92afb382bcb38a9f2b1315ae
name: upload_file
sha1: 34b02a543a0147a245861c0b9df756e81561fd70
sha256: c208e1ec65a3bbfa95c6afc65532d2aeacf5a32baf4904853fee56f8b827e020
sha512: 38b029ac5906bb99a96dc1458732a37c91a119d39c43aff37d85ab157e41b51349cd38a11ddfa2d3aa07c6f84c210e1ac51243101689882a029683569aca9ea0
ssdeep: 6144:/RYd/lTOv+I9pmW5ZEylU77e570oStiZOkcEB6AZxYNqo:gtm+I/Rwve5IoStqH8kxYN
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1993 G23F28A8;;6=5D3:
Assembly Version: 1.0.0.0
InternalName: bash.exe
FileVersion: 2.2.3.3
CompanyName: G23F28A8;;6=5D3:
Comments: BCFFF=>@?CEFH::9H<J9=D
ProductName: 6B;;E8HE99@?47JFFD@H24F
ProductVersion: 2.2.3.3
FileDescription: 6B;;E8HE99@?47JFFD@H24F
OriginalFilename: bash.exe

Backdoor:MSIL/AsyncRAT!MSR also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.56514
MicroWorld-eScanTrojan.GenericKD.34688790
Qihoo-360Generic/HEUR/QVM03.0.63A7.Malware.Gen
ALYacTrojan.GenericKD.34688790
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34688790
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.43a014
TrendMicroTROJ_GEN.R01FC0DJ820
BitDefenderThetaGen:NN.ZemsilF.34298.Bm0@aqMPHph
CyrenW32/Trojan.UWJG-9028
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
AlibabaBackdoor:MSIL/AsyncRAT.45cd8828
ViRobotTrojan.Win32.Z.Wacatac.448000.A
Ad-AwareTrojan.GenericKD.34688790
EmsisoftTrojan.GenericKD.34688790 (B)
ComodoMalware@#xrxrfupg08m2
F-SecureBackdoor.BDS/Redcap.lnhyq
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/GenMlwB
FireEyeGeneric.mg.6d27ac6f92afb382
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraBDS/Redcap.lnhyq
MicrosoftBackdoor:MSIL/AsyncRAT!MSR
ArcabitTrojan.Generic.D2114F16
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
GDataTrojan.GenericKD.34688790
CynetMalicious (score: 85)
McAfeeRDN/GenMlwB
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.DiscordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YBB
TrendMicro-HouseCallTROJ_GEN.R01FC0DJ820
FortinetPossibleThreat
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor:MSIL/AsyncRAT!MSR?

Backdoor:MSIL/AsyncRAT!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment