Backdoor

Should I remove “Backdoor:MSIL/DCRat.GG!MTB”?

Malware Removal

The Backdoor:MSIL/DCRat.GG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/DCRat.GG!MTB virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:MSIL/DCRat.GG!MTB?


File Info:

name: FB41E1B1581B31F961F4.mlw
path: /opt/CAPEv2/storage/binaries/5aa4af2a499fc0bd6f3a65e5ab5bf5a66ffd20779c60cae76bcb41144dbb08df
crc32: 4D3AC3B7
md5: fb41e1b1581b31f961f4b9144cb7603c
sha1: e41b9212c43a5aa0aba63eaa0e868c5e969bfbc5
sha256: 5aa4af2a499fc0bd6f3a65e5ab5bf5a66ffd20779c60cae76bcb41144dbb08df
sha512: d08afd113e9dc941ab626049a9ac8bfedb5a2fde788cc473cfce4ed909426a5c11ccde6c6313797a2f5db4b48dfd129c8075535bad91bf963375dab1ccf76580
ssdeep: 24576:gcqbBXNCnFGAT9nE+5VmgFWhp2Wd7hKN0OFjX6OYJQI3SJKPWGDai2t+4:g7bx4oA97czhWFu+5s+GDo0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E556B123A44CE02E1691A3BD9EF805447ACED417A72DB1A7E6F339D65523A70E0E1CF
sha3_384: d200d71591640f7f08adb82b21f93c1788120e996d9b5d9cb74ad5c997d93924d80ff901b68b78174630c948ca335e4b
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-21 01:09:22

Version Info:

ProductName: CwRrreIELDFMT4fqmNpSwR
CompanyName: VHnyJGZvhW
InternalName: NykjPAwfDVGE9UwXLshNT.exe
LegalCopyright: H5Vh697vQq0djIlI8p1bO8O
Comments: mLk
OriginalFilename: NL9JYeXcUaDwhREjNWfTgC.exe
ProductVersion: 18.812.247.512
FileVersion: 301.231.92.794
Translation: 0x0409 0x0514

Backdoor:MSIL/DCRat.GG!MTB also known as:

LionicTrojan.MSIL.Stealer.l!c
Elasticmalicious (high confidence)
DrWebBackDoor.QuasarNET.5
MicroWorld-eScanIL:Trojan.MSILZilla.9872
FireEyeGeneric.mg.fb41e1b1581b31f9
McAfeeArtemis!FB41E1B1581B
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2586614
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:MSIL/Stealer.1bcd1656
K7GWSpyware ( 005807381 )
K7AntiVirusSpyware ( 005807381 )
BitDefenderThetaGen:NN.ZemsilF.34114.ur0@aq27CIii
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DEK
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Uztuby-9848412-0
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderIL:Trojan.MSILZilla.9872
NANO-AntivirusTrojan.Win32.Stealer.jjcgqh
AvastWin32:RansomX-gen [Ransom]
TencentMsil.Trojan-spy.Stealer.Edwz
Ad-AwareIL:Trojan.MSILZilla.9872
SophosML/PE-A
TrendMicroTROJ_GEN.R002C0WL521
EmsisoftIL:Trojan.MSILZilla.9872 (B)
IkarusTrojan.MSIL.Spy
AviraHEUR/AGEN.1144842
Antiy-AVLTrojan/Generic.ASMalwS.34DEBF3
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftBackdoor:MSIL/DCRat.GG!MTB
GDataIL:Trojan.MSILZilla.9872
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.DC.C4650212
VBA32TScope.Trojan.MSIL
ALYacIL:Trojan.MSILZilla.9872
MAXmalware (ai score=80)
MalwarebytesSpyware.PasswordStealer.MSIL
TrendMicro-HouseCallTROJ_GEN.R002C0WL521
YandexTrojanSpy.Agent!k6Zhxp06gQc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.DEK!tr.spy
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.1581b3
PandaTrj/CI.A
MaxSecureTrojan.Malware.73709669.susgen

How to remove Backdoor:MSIL/DCRat.GG!MTB?

Backdoor:MSIL/DCRat.GG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment