Backdoor

Backdoor:Win32/Koceg!A malicious file

Malware Removal

The Backdoor:Win32/Koceg!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Koceg!A virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Koceg!A?


File Info:

crc32: B056A9A3
md5: b4eeb8b1c741d277de1db1c7a708eba0
name: B4EEB8B1C741D277DE1DB1C7A708EBA0.mlw
sha1: ac8ec82cc54a25805046ff5d1d3a39c17de74250
sha256: 19d51921d648c5c2c250a99b1f355ca9a6a71f4f1da1e095ed5c7ae8312434a1
sha512: 34b2074a23f78096a074c56c6a92211162da8e1334fece0e628a78a195d6915bae29db25fbebb51a439a6be8277d53189db29e837462a24f7fe06ab7465c0a0b
ssdeep: 24576:OaqeGz8PceFDeeo8eeIeeUTeaas0kQWU8/E0EP:Gek8PceFDeeVeeIeeUTeaasi8s9P
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Koceg!A also known as:

BkavW32.FamVT.SockTTc.Worm
K7AntiVirusTrojan ( 0003a77a1 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Socks.4
CynetMalicious (score: 100)
CAT-QuickHealWorm.Socks.14448
ALYacBackdoor.IRCBot.ACGB
CylanceUnsafe
ZillyaWorm.Socks.Win32.21
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0003a77a1 )
Cybereasonmalicious.1c741d
BaiduWin32.Backdoor.IRCBot.a
CyrenW32/Socks.A.gen!Eldorado
SymantecW32.Mandaph
ESET-NOD32Win32/Socks.EX
APEXMalicious
AvastWin32:Injecter-AT [Trj]
ClamAVWin.Worm.Socks-12
KasperskyTrojan-Ransom.Win32.Blocker.jaxq
BitDefenderBackdoor.IRCBot.ACGB
NANO-AntivirusTrojan.Win32.Socks.wbrnt
MicroWorld-eScanBackdoor.IRCBot.ACGB
TencentTrojan.Win32.Gandcrab.q
Ad-AwareBackdoor.IRCBot.ACGB
SophosML/PE-A + Troj/DwnLdc-Gen
ComodoWorm.Win32.Socks.EX@9uvh
F-SecureTrojan.TR/Drop.Agent.snv
BitDefenderThetaAI:Packer.48611E961B
VIPREWorm.Win32.Socks.bt (fs)
TrendMicroBKDR_SMALL.JAN
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
FireEyeGeneric.mg.b4eeb8b1c741d277
EmsisoftBackdoor.IRCBot.ACGB (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Socks.al
AviraTR/Drop.Agent.snv
Antiy-AVLTrojan/Generic.ASMalwS.18462BE
MicrosoftBackdoor:Win32/Koceg.gen!A
ArcabitBackdoor.IRCBot.ACGB
ZoneAlarmTrojan-Ransom.Win32.Blocker.jaxq
GDataBackdoor.IRCBot.ACGB
AhnLab-V3Worm/Win32.Socks.C86480
Acronissuspicious
McAfeeBackDoor-DOQ
MAXmalware (ai score=83)
VBA32BScope.Worm.Socks
MalwarebytesGeneric.Worm.Autorun.DDS
TrendMicro-HouseCallBKDR_SMALL.JAN
RisingRansom.Blocker!8.12A (TFE:dGZlOgVkX+xbyaUUQw)
YandexWorm.Socks!giDPU5cMz9s
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Socks.HF!worm
AVGWin32:Injecter-AT [Trj]

How to remove Backdoor:Win32/Koceg!A?

Backdoor:Win32/Koceg!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment