Backdoor

Backdoor:Win32/AsyncRAT removal tips

Malware Removal

The Backdoor:Win32/AsyncRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/AsyncRAT virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:Win32/AsyncRAT?


File Info:

name: 757D4515D5B70AC33E4B.mlw
path: /opt/CAPEv2/storage/binaries/bea96884de01f3737f6d8ee9d134ddc4d86f528032055058605c799f379880d6
crc32: 4C25327B
md5: 757d4515d5b70ac33e4b4daa72a69738
sha1: a5b796a652a4f0f17aeaae8bfe43acaac1a1c561
sha256: bea96884de01f3737f6d8ee9d134ddc4d86f528032055058605c799f379880d6
sha512: d058f42783031bb320901981fac82576c4e42a43a3a70cb5fecbde8642b4131c93b11b9a00d525d6d151096346f8779b281e1437c781e94670d5b02773f8a9fd
ssdeep: 24576:WNA3R5drXPbrw9NFdtunr+4V01ms0L0afT/F4dTkS8bqPXrWUSCc/q2S:35jc1enrTSUs057F4g+X9TF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12345BC81A6E04762D16D153629ADBAF094ECFD2C1A10CEDF22F4EB18963374FD313666
sha3_384: ec36aaed412133bfa1bc3ee8239b2e497f67c622d38b82b469ed3d64badd9f1f2e43ed21e72099740728a7b735b2c295
ep_bytes: e85a040000e98efeffff3b0dc8a14300
timestamp: 2019-04-27 20:03:27

Version Info:

0: [No Data]

Backdoor:Win32/AsyncRAT also known as:

BkavW32.Common.7FEFDA82
LionicTrojan.Win32.Redcap.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.69123037
FireEyeGeneric.mg.757d4515d5b70ac3
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!757D4515D5B7
Cylanceunsafe
SangforDropper.Bat.Agent.V389
AlibabaTrojanDropper:BAT/Redcap.bef3f56b
K7GWTrojan ( 005592e51 )
K7AntiVirusTrojan ( 005592e51 )
VirITTrojan.Win32.Genus.SYC
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/TrojanDropper.Agent.NJJ
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DAO24
Paloaltogeneric.ml
ClamAVWin.Dropper.QuasarRAT-10014890-0
KasperskyTrojan.MSIL.Hesv.exj
BitDefenderTrojan.GenericKD.69123037
NANO-AntivirusTrojan.Win32.Redcap.kcjhsa
AvastWin32:Malware-gen
TencentWin32.Trojan.Ad.Rsmw
EmsisoftTrojan.GenericKD.69123037 (B)
F-SecureTrojan.TR/Redcap.vqiwb
DrWebTrojan.Siggen21.23787
VIPRETrojan.GenericKD.69123037
TrendMicroTROJ_GEN.R002C0DAO24
SophosMal/Generic-S
IkarusTrojan.Autoit
AviraTR/AD.Nekark.kkhmd
VaristW32/ABRisk.BVTM-3388
Antiy-AVLTrojan/Win32.Synder
KingsoftWin32.Hack.Unknown.a
MicrosoftBackdoor:Win32/AsyncRAT
XcitiumMalware@#2eg2gynm63wh3
ArcabitTrojan.Generic.D41EBBDD
ZoneAlarmTrojan.MSIL.Hesv.exj
GDataTrojan.GenericKD.69123037
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Bladabindi.R589573
VBA32Backdoor.AsyncRAT
ALYacTrojan.GenericKD.69123037
MalwarebytesMalware.AI.1324035134
PandaTrj/Chgt.AD
ZonerProbably Heur.RARAutorun
MAXmalware (ai score=85)
MaxSecureTrojan.Malware.216516247.susgen
FortinetBAT/Agent.NJJ!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudTrojan:MSIL/Synder

How to remove Backdoor:Win32/AsyncRAT?

Backdoor:Win32/AsyncRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment