Malware

Mal/Generic-R + Troj/Backdr-ID removal tips

Malware Removal

The Mal/Generic-R + Troj/Backdr-ID is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Backdr-ID virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics
  • Contains RAT configuration for DarkComet (see Static Analysis tab)

How to determine Mal/Generic-R + Troj/Backdr-ID?


File Info:

crc32: BB50E9E3
md5: cf87d7e808faec9cfd1d2dc39a80d634
name: CF87D7E808FAEC9CFD1D2DC39A80D634.mlw
sha1: 43aa7194671f56326b06df68662994e8c5b2901e
sha256: f593910c588856c47056520d2edf93ebd4bd9ae9c68205d657aac26276d65e82
sha512: cb6b840b6b3896133f0a0dda6ee836cab7b9f8ab7e790853340e079db7800636a55285b05701f9c4cc8d68db38d40a8c78c2d28566b5395a767706a1d20b66c4
ssdeep: 12288:C9HFJ9rJxRX1uVVjoaWSoynxdO1FVBaOiRZTERfIhNkNCCLo9Ek5C/hdrzm:uZ1xuVVjfFoynPaVBUR8f+kN10EB3zm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: MSRSAAPP
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corp.
Comments: Remote Service Application
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0
FileDescription: Remote Service Application
OriginalFilename: MSRSAAP.EXE
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/Backdr-ID also known as:

BkavW32.FamVT.DeagezLQ.Trojan
Elasticmalicious (high confidence)
DrWebBackDoor.Tordev.976
MicroWorld-eScanTrojan.Inject.AUZ
FireEyeGeneric.mg.cf87d7e808faec9c
CAT-QuickHealBackdoor.Fynloski.A9
Qihoo-360Win32/Backdoor.DarkKomet.A
McAfeeGeneric BackDoor.xa
CylanceUnsafe
VIPREBackdoor.Win32.Fynloski.A (v)
SangforWin.Trojan.DarkKomet-1
K7AntiVirusBackdoor ( 003b505d1 )
BitDefenderTrojan.Inject.AUZ
K7GWBackdoor ( 003b505d1 )
Cybereasonmalicious.808fae
BitDefenderThetaAI:Packer.673611681C
CyrenW32/Fynloski.JQOL-9129
SymantecBackdoor.Graybird
TotalDefenseWin32/Fynloski.A!generic
APEXMalicious
AvastMSIL:GenMalicious-CHX [Trj]
ClamAVWin.Trojan.DarkKomet-1
KasperskyBackdoor.Win32.DarkKomet.xyk
AlibabaBackdoor:Win32/Fynloski.3cfc3724
NANO-AntivirusTrojan.Win32.DarkKomet.ecawjb
ViRobotBackdoor.Win32.Agent.674304.A
RisingBackdoor.DarkComet!1.CB87 (CLASSIC)
Ad-AwareTrojan.Inject.AUZ
TACHYONBackdoor/W32.DP-DarkKomet.774656
SophosMal/Generic-R + Troj/Backdr-ID
ComodoBackdoor.Win32.Agent.XAB@4of2bc
F-SecureBackdoor.BDS/DarkKomet.GS
BaiduWin32.Backdoor.Agent.l
ZillyaBackdoor.DarkKomet.Win32.30208
TrendMicroBKDR_FYNLOS.SMM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bh
EmsisoftTrojan.Inject.AUZ (B)
IkarusTrojan.Win32.Bredolab
JiangminTrojan/Generic.adygq
Webroot
AviraBDS/DarkKomet.GS
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet.xyk
KingsoftWin32.Hack.HuigeziT.cz.(kcloud)
MicrosoftBackdoor:Win32/Fynloski.PA!MTB
GridinsoftBackdoor.Win32.Fynloski.zv!n
ArcabitTrojan.Inject.AUZ
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
ZoneAlarmBackdoor.Win32.DarkKomet.xyk
GDataWin32.Backdoor.DarkComet.H
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Keylogger.679832
Acronissuspicious
VBA32Backdoor.Tordev
ALYacTrojan.Inject.AUZ
MAXmalware (ai score=100)
MalwarebytesBladabindi.Backdoor.Njrat.DDS
PandaTrj/Packed.B
ZonerTrojan.Win32.88734
ESET-NOD32Win32/Fynloski.AA
TrendMicro-HouseCallBKDR_FYNLOS.SMM
TencentBackdoor.Win32.Darkkomet.a
YandexTrojan.Comet.Gen.LO
SentinelOneStatic AI – Malicious PE
eGambitRAT.DarkComet
FortinetW32/Generic.AC.25E!tr
AVGMSIL:GenMalicious-CHX [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureBackdoor.DarkComet

How to remove Mal/Generic-R + Troj/Backdr-ID?

Mal/Generic-R + Troj/Backdr-ID removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment