Backdoor

Backdoor:Win32/Flacher.A!dha removal tips

Malware Removal

The Backdoor:Win32/Flacher.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Flacher.A!dha virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Flacher.A!dha?


File Info:

name: 5C42EC22DA050BBC82E4.mlw
path: /opt/CAPEv2/storage/binaries/1c9af096e4c7daa440af136f2b1439089a827101098cfe25b8c19fc7321eaad9
crc32: A9A5901F
md5: 5c42ec22da050bbc82e4a86d4dd0e086
sha1: c2b09f227d141befeab81df132c9abbad4b73c46
sha256: 1c9af096e4c7daa440af136f2b1439089a827101098cfe25b8c19fc7321eaad9
sha512: 6c371d3026e2c0ef97daf85427df55b32a5b20b8ae7c1dbaa6476194b867c852aec6c67bb9656b930413dd2036a8f5d5d93a916a8d4725d4f430a2cd48f423b0
ssdeep: 6144:Ph8hP8rkktiTWdEAF2x3TdtS23OIvnwUh8u9hK/:Akj2xnnw3WA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199449D117AE1C873E5B301334956C329A7B7BC20AD36861B77D43F4DEE312929B29792
sha3_384: b15c4b98d49112d2c2363275a5c52231b1d74fb87350e21fc06a1372f1bd3c8bf79679ade64b72e35a7b4ace4f60e39c
ep_bytes: e866730000e916feffff558bec51538b
timestamp: 2012-04-26 16:33:48

Version Info:

0: [No Data]

Backdoor:Win32/Flacher.A!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Flacher.a!c
FireEyeGeneric.mg.5c42ec22da050bbc
SkyhighBackdoor-Flacher
McAfeeBackdoor-Flacher
MalwarebytesMalware.AI.4229632269
ZillyaDownloader.Agent.Win32.153804
SangforBackdoor.Win32.Flacher.Vx0h
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaBackdoor:Win32/Flacher.08f8e90f
K7GWSpyware ( 0055e3db1 )
VirITTrojan.Win32.Agent2.BHYH
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Agent.OCR
APEXMalicious
TrendMicro-HouseCallTROJ_FLACHER.A
ClamAVWin.Downloader.Agent-581752
KasperskyTrojan-Downloader.Win32.Agent.gyuo
NANO-AntivirusTrojan.Win32.Agent.bkxgxh
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10be8ccd
GoogleDetected
DrWebBackDoor.QuakBot.1
TrendMicroTROJ_FLACHER.A
SophosMal/Generic-S
IkarusTrojan-Dropper.Agent
JiangminTrojanDownloader.Agent.ecpe
VaristW32/Kryptik.ENN.gen!Eldorado
Antiy-AVLTrojan[APT]/Win32.Wildneutron
Kingsoftmalware.kb.a.984
MicrosoftBackdoor:Win32/Flacher.A!dha
XcitiumMalware@#a0v16cs3miv4
ZoneAlarmTrojan-Downloader.Win32.Agent.gyuo
AhnLab-V3Trojan/Win32.Downloader.R134042
VBA32TrojanDownloader.Agent
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/CI.A
RisingBackdoor.Flacher!8.482B (TFE:5:8uvlhpuD9gC)
YandexTrojan.GenAsa!usX/ryim+yA
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.4923693.susgen
FortinetW32/Agent.OCR!tr.spy
BitDefenderThetaGen:NN.ZexaF.36802.rqW@aSf3Mqki
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudBackdoor

How to remove Backdoor:Win32/Flacher.A!dha?

Backdoor:Win32/Flacher.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment