Backdoor

Backdoor:Win32/Escad.AA!dha removal tips

Malware Removal

The Backdoor:Win32/Escad.AA!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Escad.AA!dha virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Escad.AA!dha?


File Info:

name: 2618DD3E5C59CA851F03.mlw
path: /opt/CAPEv2/storage/binaries/201a9c5fe6a8ae0d1c4312d07ef2066e5991b1462b68f102154bb9cb25bf59f9
crc32: FD2F439A
md5: 2618dd3e5c59ca851f03df12c0cab3b8
sha1: cb39c8639a2f74a3424d040d22a856859ab559a8
sha256: 201a9c5fe6a8ae0d1c4312d07ef2066e5991b1462b68f102154bb9cb25bf59f9
sha512: 6b5260917e2351df012b1b264129331977b2bb3203e98f33850563a0c9d338dd6bcb023e722b165ee22f4d3d565d8e372c7e14d60289f18bdb28a317dffc1d7a
ssdeep: 12288:aMts4GtTpnVsvL6wh9KRyJxUK5fJJiyQM9sTaDR9:ltsXtTNVDw9KirUytJDR9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F89423018A91C7F7C4B8563CB8DB023EA72B730996D19D93B7CDDEB420D7651B1222CA
sha3_384: 49a8d1277ae7a2e0969f484ce080d775ae35ddc370ac9ab1e57e03c6f4376b6c42370bf9bd9ab1cacbb3635cd15493c8
ep_bytes: 558bec6aff68a8b64000686079400064
timestamp: 2014-11-22 00:05:02

Version Info:

0: [No Data]

Backdoor:Win32/Escad.AA!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.toWe
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.58347
MicroWorld-eScanGen:Variant.Jaik.66403
FireEyeGeneric.mg.2618dd3e5c59ca85
SkyhighBehavesLike.Win32.Dropper.gc
ALYacBackdoor.Destover.A
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Jaik.66403
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004b65791 )
BitDefenderGen:Variant.Jaik.66403
K7GWTrojan ( 004b65791 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.AqZ@aCnGWVmG
VirITTrojan.Win32.Generic.ALEB
SymantecBackdoor.Destover
ESET-NOD32Win32/NukeSped.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-1388728
KasperskyTrojan.Win32.Agentb.bkob
AlibabaBackdoor:Win32/Escad.5777e82e
NANO-AntivirusTrojan.Win32.Generic.dnkqer
ViRobotDropper.S.Agent.440713
RisingBackdoor.Escad!8.18BD (TFE:5:OaLPI4N43QC)
EmsisoftGen:Variant.Jaik.66403 (B)
F-SecureHeuristic.HEUR/AGEN.1340331
ZillyaTrojan.Agentb.Win32.6518
TrendMicroBKDR_WIPALL.D
Trapminemalicious.moderate.ml.score
IkarusTrojan.Win32.NukeSped
JiangminTrojan.Agentb.ndh
WebrootBackdoor.Destover
VaristW32/Trojan.OOGA-3698
AviraHEUR/AGEN.1340331
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agentb
Kingsoftmalware.kb.a.999
MicrosoftBackdoor:Win32/Escad.AA!dha
XcitiumMalware@#2jldkwjplzvv9
ArcabitTrojan.Jaik.D10363
ZoneAlarmTrojan.Win32.Agentb.bkob
GDataGen:Variant.Jaik.66403
GoogleDetected
AhnLab-V3Dropper/Win32.Agent.C650405
McAfeeTrojan-Wiper
TACHYONTrojan/W32.Agentb.440713
DeepInstinctMALICIOUS
VBA32Trojan.Agentb
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_WIPALL.D
TencentMalware.Win32.Gencirc.115db569
YandexTrojan.Agentb!L8edQNaRbw0
SentinelOneStatic AI – Suspicious PE
FortinetW32/Wiper.SNAT!tr
AVGWin32:Destover-B [Trj]
Cybereasonmalicious.39a2f7
AvastWin32:Destover-B [Trj]

How to remove Backdoor:Win32/Escad.AA!dha?

Backdoor:Win32/Escad.AA!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment