Backdoor

Backdoor:Win32/Koceg.B removal tips

Malware Removal

The Backdoor:Win32/Koceg.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Koceg.B virus can do?

  • Expresses interest in specific running processes
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

infulizing.cn
www.infulizing.cn
hq-pharma.org

How to determine Backdoor:Win32/Koceg.B?


File Info:

crc32: 0489A6E0
md5: 16296ce7c30ebd374ae5d388bfe0f0e4
name: 16296CE7C30EBD374AE5D388BFE0F0E4.mlw
sha1: 4b33b7eac1578e7f6c10092ed50c9ea63fcae7a4
sha256: 7f78abf15f54900db1588c6d4be94b9b321e8ef43c60ecfc15b85a643b3af07a
sha512: 871964a42cfcce5e1eb410149dd4106a30d6836b576402ce53e3359c41f3a94b20c7eb867539d761a6589a5e761e8910b855856274275c5aba882918204cb333
ssdeep: 12288:PMy/y/yS5sy/yS5S+m+m+m+m+m+m+m+byzRMh:P1aa2aZzWh
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Koceg.B also known as:

BkavW32.AIDetect.malware1
K7AntiVirusEmailWorm ( 005327291 )
LionicTrojan.Win32.Generic.l92u
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.42350
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Agent.8448
ALYacTrojan.Downloader.Small.AAKR
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.46918
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Autorun.986c174e
K7GWEmailWorm ( 005327291 )
Cybereasonmalicious.7c30eb
BaiduWin32.Trojan-Downloader.Agent.au
CyrenW32/Backdoor.OQGQ-5196
SymantecDownloader
ESET-NOD32a variant of Win32/Socks.NAL
APEXMalicious
AvastWin32:Injecter-AT [Trj]
ClamAVWin.Worm.Socks-7102088-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.Small.AAKR
NANO-AntivirusTrojan.Win32.Agent.iiwsm
MicroWorld-eScanTrojan.Downloader.Small.AAKR
TencentMalware.Win32.Gencirc.10b0df23
Ad-AwareTrojan.Downloader.Small.AAKR
SophosML/PE-A + Mal/Koceg-A
ComodoBackdoor.Win32.Agent.ETW@ogm
BitDefenderThetaAI:Packer.894F9A351B
VIPREWorm.Win32.Socks.bt (fs)
TrendMicroBKDR_SMALL.JAN
McAfee-GW-EditionBehavesLike.Win32.Backdoor.hc
FireEyeGeneric.mg.16296ce7c30ebd37
EmsisoftTrojan.Downloader.Small.AAKR (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agent.awhh
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan/Generic.ASMalwS.762366
MicrosoftBackdoor:Win32/Koceg.B
SUPERAntiSpywareTrojan.Agent/Gen-AutoRun
GDataTrojan.Downloader.Small.AAKR
AhnLab-V3Trojan/Win32.Agent.C3545
Acronissuspicious
McAfeeGenericRXAA-AA!16296CE7C30E
MAXmalware (ai score=83)
VBA32BScope.TrojanDownloader.Small
MalwarebytesMalware.AI.423755880
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_SMALL.JAN
RisingTrojan.Agent!1.6618 (CLASSIC)
YandexBackdoor.Agent!PnZb8IhwbWk
IkarusTrojan-Downloader.Win32.Small
FortinetW32/Socks.NAK!tr
AVGWin32:Injecter-AT [Trj]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Koceg.B?

Backdoor:Win32/Koceg.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment