Backdoor

Backdoor:MSIL/RevengeRat.A!ibt information

Malware Removal

The Backdoor:MSIL/RevengeRat.A!ibt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/RevengeRat.A!ibt virus can do?

  • Network activity detected but not expressed in API logs

How to determine Backdoor:MSIL/RevengeRat.A!ibt?


File Info:

crc32: 7FD3E461
md5: 1559b97a6fe6efb93d06a2a26f0f363d
name: 1559B97A6FE6EFB93D06A2A26F0F363D.mlw
sha1: 0951d2aa8732b4bccfe457956b4d4eb4cb23bad3
sha256: 1e224bc02434f7617b56927f0cd903291fd1154d017e35cea09e96e9931f9b77
sha512: da00c4585a7d5a00b84fce4ce7c9fe219a3d521f73b0bb19139cbc3699e275f13feb7d1138ca9f38bd586018c28ce5cafe5a60ed9f502ece1a13e39cb9fca723
ssdeep: 1536:6dFCx+sysJsYsonIK49pmsxHtBbONbcAate3Gw:wFCW5brW8ct
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: WindowsApplication1.exe
FileVersion: 1.0.0.0
ProductName: WindowsApplication1
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication1
OriginalFilename: WindowsApplication1.exe

Backdoor:MSIL/RevengeRat.A!ibt also known as:

K7AntiVirusTrojan ( 0052fcde1 )
LionicTrojan.MSIL.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.RevetRat.2
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30772351
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0052fcde1 )
Cybereasonmalicious.a6fe6e
SymantecTrojan.Revetrat
ESET-NOD32a variant of MSIL/Kryptik.NWR
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderTrojan.GenericKD.30772351
MicroWorld-eScanTrojan.GenericKD.30772351
TencentMalware.Win32.Gencirc.114d0503
Ad-AwareTrojan.GenericKD.30772351
SophosMal/Generic-S
ComodoTrojWare.MSIL.Agent.GH@60rvah
BitDefenderThetaGen:NN.ZemsilF.34266.dm0@auANIMf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.1559b97a6fe6efb9
EmsisoftTrojan.GenericKD.30772351 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.261453D
MicrosoftBackdoor:MSIL/RevengeRat.A!ibt
ArcabitTrojan.Generic.D1D58C7F
GDataTrojan.GenericKD.30772351
AhnLab-V3Trojan/Win32.Bladabindi.C2444951
McAfeeArtemis!1559B97A6FE6
MAXmalware (ai score=100)
MalwarebytesMalware.AI.41855704
PandaTrj/GdSda.A
YandexTrojan.Agent!W46yoiK03lw
FortinetMSIL/GenKryptik.BYLN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor:MSIL/RevengeRat.A!ibt?

Backdoor:MSIL/RevengeRat.A!ibt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment