Backdoor

What is “Backdoor:Win32/Senarw.A”?

Malware Removal

The Backdoor:Win32/Senarw.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Senarw.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Senarw.A?


File Info:

name: 50A10E2888988D1FEC72.mlw
path: /opt/CAPEv2/storage/binaries/bf225ee62bdad6174cff0afae67af3f95b1398232cc3589b07149922b942a1f2
crc32: 2AAA575B
md5: 50a10e2888988d1fec72afaf6f6f1c5f
sha1: 3eeddeadcc34b89fbdd77384b2b97daff4ccf8cc
sha256: bf225ee62bdad6174cff0afae67af3f95b1398232cc3589b07149922b942a1f2
sha512: 17c44293b792d08e552857e413ab4b519036612ee3d3d6648d27e8d49aea12ec541fc9cfc0015de22591bb36ad361733b6e3789c17c3f32d24059eba5b917d40
ssdeep: 24576:YH4oCOWDAFL0VnwyIunXaErWvKpifswkPDd3bXZhwUwaznTyTFqo:YHURUKpiU1dL/b7TyTFqo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163659F22F6814437D2532A748C1B93A96935BF302E6469877BF93D4C9F3A78278243D7
sha3_384: adbd1804dc4a3aa5cbe5de8dbfe83849677f85a7c21ae40292ede9555906c347c1768e0b332db4bdc91ea6601a96fc91
ep_bytes: 743f0000ffffffff0500000068776964
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Senarw.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.50a10e2888988d1f
SkyhighGeneric backdoor.wr
McAfeeArtemis!50A10E288898
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Babyshark.190225
BitDefenderThetaGen:NN.ZexaF.36792.wHY@aOYNYhh
SymantecTrojan.Gen.2
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Malware-gen
F-SecureBackdoor.BDS/Siggen.nclqh
DrWebBackDoor.Siggen2.3188
SophosMal/Generic-S
IkarusBackdoor.Win32.Senarw
WebrootW32.Trojan.Gen
VaristW32/Delf.VJTZ-6408
AviraBDS/Siggen.nclqh
MAXmalware (ai score=99)
Antiy-AVLTrojan[Backdoor]/Win32.Senarw
Kingsoftmalware.kb.a.995
MicrosoftBackdoor:Win32/Senarw.A
GDataWin32.Backdoor.Sarwent.A
GoogleDetected
ALYacTrojan.Agent.1364480B
VBA32Backdoor.Senarw
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.KillAV!1.A2ED (CLASSIC)
YandexBackdoor.Siggen!HVlrAPo3kAM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.101886698.susgen
FortinetW32/BDoor.BHO!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Senarw.A?

Backdoor:Win32/Senarw.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment