Backdoor

Backdoor:Win32/Flawedammyy!mclg removal guide

Malware Removal

The Backdoor:Win32/Flawedammyy!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Flawedammyy!mclg virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Appears to use command line obfuscation
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Flawedammyy!mclg?


File Info:

name: 63E5BD9536EFAB04E2EB.mlw
path: /opt/CAPEv2/storage/binaries/f730e47542725766bc407b0e2cbe648d3148ed11de8a6eeb16d7a6c8a72b2ee7
crc32: E0D2DA50
md5: 63e5bd9536efab04e2ebc65bb8866c19
sha1: f9c5225b929ea8862ea2d12a706b89abae3953a5
sha256: f730e47542725766bc407b0e2cbe648d3148ed11de8a6eeb16d7a6c8a72b2ee7
sha512: 31034ad597de43a5f8fb46fa67de2b1203cf51a2e14066f5fc6d272dc3c4845ab954975662d5438eb7edf8e834c0e912eb35e7c3c23770f0f0fd6ef6297402bf
ssdeep: 98304:Xvmv630Vlq1rIPh8gZ+lsl9uiV2BtrdQZgiPFgtMG:XvY63kP6lsSxtBdiPMMG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1222633133F99D851F38014BA7191F85B8B65DCAB7E56D51B85203A7F1BFABA28E12003
sha3_384: 58abdb15a3baa7b4da5143d5d473377dd11eab92355a4002dfa91d989cc28efede4f56f6bcb77cb8d287e3db27304e6e
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2018-12-15 22:24:01

Version Info:

Comments: TVRNKMPMTP
CompanyName: Chrisbanks2-Cold-Fusion-Hd-Zynga-Poker.ico
FileVersion: 5.0.2.1
LegalCopyright: TVRNKMPMTP inc 2020
LegalTrademarks: TVRNKMPMTP company
ProductName: Chrisbanks2-Cold-Fusion-Hd-Zynga-Poker
Translation: 0x0409 0x04e4

Backdoor:Win32/Flawedammyy!mclg also known as:

LionicTrojan.PowerShell.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47504803
FireEyeGeneric.mg.63e5bd9536efab04
ALYacTrojan.GenericKD.47504803
CylanceUnsafe
SangforTrojan.Powershell.Generic.ky
K7AntiVirusTrojan ( 0056c7ab1 )
K7GWTrojan ( 0056c7ab1 )
CrowdStrikewin/malicious_confidence_60% (W)
ESET-NOD32NSIS/Agent.NCP
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.PowerShell.Generic
BitDefenderTrojan.GenericKD.47504803
AvastWin32:Trojan-gen
TencentWin32.Trojan.Falsesign.Wqdh
TrendMicroTrojan.PS1.POWSPLOIT.SM
SophosMal/Generic-S
AviraHEUR/AGEN.1134962
MicrosoftBackdoor:Win32/Flawedammyy!mclg
GDataTrojan.GenericKD.47504803
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R454140
McAfeeArtemis!63E5BD9536EF
MAXmalware (ai score=88)
VBA32Trojan.Script.Wacatac
MalwarebytesMalware.AI.4233722259
TrendMicro-HouseCallTrojan.PS1.POWSPLOIT.SM
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
FortinetNSIS/Agent.C!tr
AVGWin32:Trojan-gen

How to remove Backdoor:Win32/Flawedammyy!mclg?

Backdoor:Win32/Flawedammyy!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment