Backdoor

About “MemScan:Backdoor.Generic.474970” infection

Malware Removal

The MemScan:Backdoor.Generic.474970 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Backdoor.Generic.474970 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the PoisonIvy malware family
  • Creates a copy of itself
  • Attempts to masquerade or mimic a legitimate process or file name
  • Anomalous binary characteristics

How to determine MemScan:Backdoor.Generic.474970?


File Info:

name: 39A5AB240A423BF6F361.mlw
path: /opt/CAPEv2/storage/binaries/5e52e13a5791f474ff431136756525b69207fb76673b40227087c249a294e5c7
crc32: C31F3855
md5: 39a5ab240a423bf6f3610fef959af15b
sha1: 74be8c58229e8c5c1ab50e1006c4f17d52c686cf
sha256: 5e52e13a5791f474ff431136756525b69207fb76673b40227087c249a294e5c7
sha512: 0e34bea50e674b011960e1552b3079f7cb6f9b88d7834cf61f10a51912d80c9ea666e42567991d59b24121cec38de2dcac4cee77715a8abc171676e90aaf6fa8
ssdeep: 1536:DwmUBoGYyUUrWqi54hxmYdsinXfjBribmzTGO0pAFNXdtl3ZOVI8X0DJU:DNU4UrsUmQ1+mzIAFFdtl3ZO6b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137730152E697892DE893113B11C0841C46229F6352E64A5FAFD0FD1EBDBF2A2BC44F74
sha3_384: 7c7a55b69a633d171ddad75b70d6c522f595c9e00c06d7235ce333940af1cd6950c2437667e7b70a647faa9ed6dc5b88
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2011-01-14 04:54:12

Version Info:

0: [No Data]

MemScan:Backdoor.Generic.474970 also known as:

LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanMemScan:Backdoor.Generic.474970
FireEyeGeneric.mg.39a5ab240a423bf6
McAfeeArtemis!39A5AB240A42
CylanceUnsafe
VIPREMemScan:Backdoor.Generic.474970
SangforTrojan.Win32.MultiPacked.A
K7AntiVirusRiskware ( 0015e4f01 )
AlibabaTrojan:Win32/Malex.3a60ab1d
K7GWRiskware ( 0015e4f01 )
Cybereasonmalicious.40a423
BaiduWin32.Trojan-Dropper.Agent.cm
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.MultiPacked.A
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agentb.jan
BitDefenderMemScan:Backdoor.Generic.474970
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Agentb.Jajl
Ad-AwareMemScan:Backdoor.Generic.474970
EmsisoftMemScan:Backdoor.Generic.474970 (B)
ComodoTrojWare.Win32.TrojanDropper.VB.sx@4oxh1p
DrWebBackDoor.Poison.19147
ZillyaBackdoor.Poison.Win32.50323
TrendMicroTROJ_GEN.R002C0DHV22
McAfee-GW-EditionGenericRXCT-VV!228315CC20D1
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataMemScan:Backdoor.Generic.474970
WebrootW32.Malware.Gen
AviraTR/Crypt.ASPM.Gen2
ZoneAlarmTrojan.Win32.Agentb.jan
MicrosoftTrojan:Win32/Occamy.C5E
GoogleDetected
AhnLab-V3Trojan/Win32.Refroso.C68203
BitDefenderThetaAI:Packer.302058F520
ALYacMemScan:Backdoor.Generic.474970
MAXmalware (ai score=100)
VBA32Trojan.Wacatac
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002C0DHV22
RisingBackdoor.Win32.PoisonIvy.aew (CLOUD)
YandexTrojan.DR.Agent!A5uHB8DpfV4
IkarusVirus.Win32.VBInject
MaxSecureTrojan.Malware.2996434.susgen
AVGWin32:Evo-gen [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MemScan:Backdoor.Generic.474970?

MemScan:Backdoor.Generic.474970 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment