Backdoor

Should I remove “Backdoor:Win32/Death.2_5”?

Malware Removal

The Backdoor:Win32/Death.2_5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Death.2_5 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Death.2_5?


File Info:

crc32: EC099FA1
md5: cc768b1df5f96a64bca71235efaed36e
name: CC768B1DF5F96A64BCA71235EFAED36E.mlw
sha1: 51826ae8e68775fe99ec91290efbf248726a0237
sha256: 80d2147d88e2abb3cdead0db677005f87da8caffec9314e5fb87dc8d1a391a26
sha512: e6721f58967ee5dc9d707ca8cc240164cea8441cdb6c2ccd4c1460e3c0e1d9f3ede0ac393c790986632e8cb72c47e4f9d9d49c14b7b7288114780f5a5b138408
ssdeep: 6144:p2t3Ddz9XAq2nveLMBIKYiGJu8f/SbBRwImO9PnjMmQ5u9YW6drqFw:Mi2MCEQ/6BRwig4mHN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Death.2_5 also known as:

K7AntiVirusTrojan ( 0000000c1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.12093
CynetMalicious (score: 100)
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Trojan.Heur.DP.wGZ@aGOt!Hjc
CylanceUnsafe
ZillyaBackdoor.Death.Win32.191
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaBackdoor:Win32/Death.ef27f25f
K7GWTrojan ( 0000000c1 )
Cybereasonmalicious.df5f96
CyrenW32/Backdoor.ZERP-8339
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Death.25.F
APEXMalicious
TotalDefenseWin32/Death.26.G/H
AvastWin32:Death-M [PUP]
ClamAVWin.Trojan.Death-9835422-0
KasperskyBackdoor.Win32.Death.25.f
BitDefenderGen:Trojan.Heur.DP.wGZ@aGOt!Hjc
NANO-AntivirusTrojan.Win32.Death.cdkxv
MicroWorld-eScanGen:Trojan.Heur.DP.wGZ@aGOt!Hjc
TencentWin32.Backdoor.Death.Taos
Ad-AwareGen:Trojan.Heur.DP.wGZ@aGOt!Hjc
SophosML/PE-A
ComodoMalware@#115aaz9zt6rqt
BitDefenderThetaAI:Packer.DF3AA8BE1F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.HLLP.fc
FireEyeGeneric.mg.cc768b1df5f96a64
EmsisoftGen:Trojan.Heur.DP.wGZ@aGOt!Hjc (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Death.l
AviraBDS/Death.25.F
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Death.25.(kcloud)
MicrosoftBackdoor:Win32/Death.2_5
ArcabitTrojan.Heur.DP.ED10242
GDataGen:Trojan.Heur.DP.wGZ@aGOt!Hjc
AhnLab-V3Dropper/Win32.Xema.C72096
Acronissuspicious
McAfeeArtemis!CC768B1DF5F9
MAXmalware (ai score=100)
VBA32Backdoor.Death
MalwarebytesMalware.AI.4206839030
PandaTrj/CI.A
RisingBackdoor.Death!8.1506 (CLOUD)
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.87825.susgen
FortinetW32/Death_25.26B!tr.bdr
AVGWin32:Death-M [PUP]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Generic.HgIASOQA

How to remove Backdoor:Win32/Death.2_5?

Backdoor:Win32/Death.2_5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment