Backdoor

What is “Backdoor:Win32/Blazgel.A”?

Malware Removal

The Backdoor:Win32/Blazgel.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Blazgel.A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Blazgel.A?


File Info:

name: AF32C1C0D72AF29BB961.mlw
path: /opt/CAPEv2/storage/binaries/2d7da125f023712d04582f4c68a19a42c2662708c8070d14ad1ebc768e353ec9
crc32: F5A30F72
md5: af32c1c0d72af29bb96174bc3ccb146a
sha1: 251c4dbc86d5df1170c424d4f30b5ed8ff620569
sha256: 2d7da125f023712d04582f4c68a19a42c2662708c8070d14ad1ebc768e353ec9
sha512: 62f19006701b85c6e1c6fc9f661edbd3e5ac38ac30f1699397c6da4ee522570963d121621ef9401d54fbbaa6b72c2be85d1d52daa13927656ce58e0f31553bc5
ssdeep: 1536:AEMWmrKiyTtIGbrY7UqONhEG+2kfa1jWWhOK:XMz3Yq4yGVkfoWW8K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A93E1827BF02AB3E8309530186F0A374DEDF526DA1287B77F80D97124BE350A909BC5
sha3_384: 3fe00d6fda9169665f9cafd5d4f8f45ff48faeb25c2216bd225b78ac9274f5021ce39227963c98e4cc4797384d575497
ep_bytes: 558bec83ec4456ff15784040008bf08a
timestamp: 2008-06-05 12:17:31

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: DirectShow Setup Tool
FileVersion: 5, 0, 2195, 9787
InternalName:
LegalCopyright: Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 5, 0, 2195, 3
SpecialBuild:
Translation: 0x0409 0x04b0

Backdoor:Win32/Blazgel.A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.af32c1c0d72af29b
SkyhighGenericRXLA-BK!AF32C1C0D72A
ALYacTrojan.Dropper.RYB
Cylanceunsafe
VIPRETrojan.Dropper.RYB
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/Blazgel.5dd91665
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Dropper.RYB
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.LYB
APEXMalicious
KasperskyTrojan.Win32.Scar.mve
BitDefenderTrojan.Dropper.RYB
NANO-AntivirusTrojan.Win32.Agent.crkpbz
MicroWorld-eScanTrojan.Dropper.RYB
AvastWin32:Agent-UDX [Trj]
TencentWin32.Trojan.Scar.Uwhl
SophosTroj/BlazDll-A
F-SecureTrojan.TR/Rootkit.Gen
DrWebBackDoor.Hbeat.61
Trapminemalicious.high.ml.score
EmsisoftTrojan.Dropper.RYB (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agent.axfs
VaristW32/Agent.CF.gen!Eldorado
AviraTR/Rootkit.Gen
Antiy-AVLTrojan/Win32.Scar
Kingsoftmalware.kb.a.1000
XcitiumBackdoor.Win32.Agent.AI29@1n1mwt
MicrosoftBackdoor:Win32/Blazgel.A
ZoneAlarmTrojan.Win32.Scar.mve
GDataTrojan.Dropper.RYB
GoogleDetected
AhnLab-V3Trojan/Win32.Malco.R7516
McAfeeGenericRXLA-BK!AF32C1C0D72A
MAXmalware (ai score=82)
VBA32BScope.Backdoor.Hbeat
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
RisingBackdoor.Win32.IRCbot.dir (CLASSIC)
YandexTrojan.GenAsa!et7hfMphzX4
IkarusTrojan-GameThief.Win32.OnLineGames
FortinetW32/Blazgel.A!tr
BitDefenderThetaAI:Packer.FA3D55731C
AVGWin32:Agent-UDX [Trj]
Cybereasonmalicious.c86d5d
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Blazgel.A?

Backdoor:Win32/Blazgel.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment