Backdoor

Should I remove “Backdoor:Win32/Winsec.D!dha”?

Malware Removal

The Backdoor:Win32/Winsec.D!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Winsec.D!dha virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Deletes executed files from disk

How to determine Backdoor:Win32/Winsec.D!dha?


File Info:

name: EE40D99C7DDE0605DDBA.mlw
path: /opt/CAPEv2/storage/binaries/49112b6739fe518dc826ee02ff11688491096f931d2ffd656c3f7b21b28656b0
crc32: 1C899A94
md5: ee40d99c7dde0605ddba163daa53a7a4
sha1: 71ded0d6cd353d4c7e3b7cc576591465cb2eb073
sha256: 49112b6739fe518dc826ee02ff11688491096f931d2ffd656c3f7b21b28656b0
sha512: 73727cc82bc46016a0c70a743ed0b8f8a2210e5c526d8d3a6c245bd669591de7b563d3dc262c5ac89bcb3805c63ab37160f8c2975f3e218532693288bd679491
ssdeep: 768:fv6//+oDIajrOVvjuu+tIJ3YdP6aX/QWVnumTKuSG0+Cx/ABKePWDTquk1PcPW/8:fk7DIajC7p+EIdMW1T0rJxvJ0PTEzh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA336C491D53D063E4830C70C7A9A5D6BFFE6DB33095B16FDF80A44814B9299D228F7A
sha3_384: f5fb6b3909920a70f2c066281cbd013906ba7413120baf6fa7090ba0ae403af113e91c8aeaf192787ea5d801b6a7c41e
ep_bytes: 558bec6aff6860814000680461400064
timestamp: 2015-06-05 00:16:38

Version Info:

CompanyName: Microsoft Corporation
FileDescription: 네트워크 액세스 보호 클라이언트 UI
FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
InternalName: napstat.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: napstat.exe.mui
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.3.9600.16384
Translation: 0x0412 0x04b0

Backdoor:Win32/Winsec.D!dha also known as:

MicroWorld-eScanGen:Variant.Fugrafa.7885
FireEyeGeneric.mg.ee40d99c7dde0605
McAfeeSuspect-CZ!EE40D99C7DDE
CylanceUnsafe
VIPREGen:Variant.Fugrafa.7885
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 004be5271 )
K7GWTrojan ( 004be5271 )
Cybereasonmalicious.c7dde0
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/NukeSped.IN
APEXMalicious
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyHEUR:Trojan-Banker.Win32.Alreay.gen
BitDefenderGen:Variant.Fugrafa.7885
AvastWin32:Crypt-RXQ [Trj]
TencentMalware.Win32.Gencirc.11d1723c
Ad-AwareGen:Variant.Fugrafa.7885
ComodoTrojWare.Win32.PSW.GamePass.C@2mkvnv
DrWebTrojan.MulDrop5.59555
ZillyaTrojan.Agent.Win32.728057
McAfee-GW-EditionNew Malware.x
EmsisoftGen:Variant.Fugrafa.7885 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Fugrafa.7885
JiangminTrojan.Banker.Alreay.bs
AviraTR/Bruter.45056.1
Antiy-AVLTrojan/Generic.ASMalwS.330C
ArcabitTrojan.Fugrafa.D1ECD
ViRobotTrojan.Win32.Agent.45056.ND
MicrosoftBackdoor:Win32/Winsec.D!dha
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Skeeyah.R500168
BitDefenderThetaGen:NN.ZexaF.34806.dq2@aKgAfpcO
ALYacGen:Variant.Fugrafa.7885
MAXmalware (ai score=85)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.2325467466
YandexTrojan.Bruter!SqLBR/1TERE
AVGWin32:Crypt-RXQ [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Backdoor:Win32/Winsec.D!dha?

Backdoor:Win32/Winsec.D!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment