Backdoor

Backdoor:Win32/Hostil!A removal

Malware Removal

The Backdoor:Win32/Hostil!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Hostil!A virus can do?

  • Executable code extraction
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
lander-dance.co.cc
rumble-fair.co.cc
laps-apiece.co.cc

How to determine Backdoor:Win32/Hostil!A?


File Info:

crc32: BE6A7497
md5: 37b0e752cda68a865d724a2f40578192
name: 37B0E752CDA68A865D724A2F40578192.mlw
sha1: 397a3a704a808a4b07aaa78e91970f522694900a
sha256: 15aabd260af43f54f340e2722f45bb6faa9d73e5229daba93f5dd5719f8744d1
sha512: 3523f932e034e495454bd1bc4bc3c60530dc1003eadc3f854c57875dfcee1aa876ba39238290be13f91eb28ad8a8ced8d01a9d352598a5c7724e5ea5cd880579
ssdeep: 768:rnLByaWWiM8FKOYLqPoqLPu6wD4M7dtBMhk86kYRvt4MExKdv4jqwPRavWwxUsM:4aaI6i9tiYRvtg645wWUU9xNjTjahT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 hNOzOzZxRK 2006-2011. All rights reserved.
InternalName: ItIuVnd
FileVersion: 1,0,4,2
CompanyName: vjnmBOqyR
ProductName: PfMdhvcSe
ProductVersion: 1,0,4,2
FileDescription: CGgDAHDtXO
OriginalFilename: zutQQzU.exe
Translation: 0x0409 0x04e4

Backdoor:Win32/Hostil!A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.763824
ALYacGen:Variant.Razy.763824
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005326e31 )
BitDefenderGen:Variant.Razy.763824
K7GWTrojan ( 005326e31 )
Cybereasonmalicious.2cda68
CyrenW32/Zbot.CP.gen!Eldorado
SymantecInfostealer.Scapzilla
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Hostil.b082bc83
NANO-AntivirusTrojan.Win32.Stealer.esfqh
AvastWin32:Hostil-B [Trj]
Ad-AwareGen:Variant.Razy.763824
EmsisoftGen:Variant.Razy.763824 (B)
ComodoTrojWare.Win32.Injector.jiw@4k97ln
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.Stealer.533
ZillyaTrojan.Injector.Win32.54765
TrendMicroRTKT_ZACESS.SM6
McAfee-GW-EditionBehavesLike.Win32.Emotet.qc
FireEyeGeneric.mg.37b0e752cda68a86
SophosMal/Generic-S
IkarusBackdoor.Win32.Hostil
JiangminTrojan/Generic.pfsn
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Hostil.gen!A
ArcabitTrojan.Razy.DBA7B0
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.763824
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.C175
McAfeeArtemis!37B0E752CDA6
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Inject.gen
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32a variant of Win32/Injector.UAS
TrendMicro-HouseCallRTKT_ZACESS.SM6
RisingTrojan.Generic@ML.100 (RDML:AWOgQyQt4UbTdPs6OcJT+A)
YandexTrojan.Injector!xtEQsf4vkIw
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Crypt.AAAH!tr
BitDefenderThetaGen:NN.ZexaF.34804.du0@aiDt@Bji
AVGWin32:Hostil-B [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Dropper.b73

How to remove Backdoor:Win32/Hostil!A?

Backdoor:Win32/Hostil!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment