Backdoor

About “MemScan:Backdoor.Generic.755288” infection

Malware Removal

The MemScan:Backdoor.Generic.755288 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Backdoor.Generic.755288 virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MemScan:Backdoor.Generic.755288?


File Info:

crc32: 6F510C6C
md5: fa0ab9c168040d836ecee5e07e2f5d19
name: FA0AB9C168040D836ECEE5E07E2F5D19.mlw
sha1: aeaed9086882f0d0e1c087ad2a706466a174e396
sha256: 645f095d3d3e1c5b71bac97a7fe92451d904fab5e90bc25999763fc706dc34c3
sha512: 4dc3b58bc8bdbda008eb59173b1e9b7dacb359d0c2fc616823b411e18b05187cb5ff940f18be1bb28e79288f0c6c04b7de00c164cb9ce9d978361603784703a7
ssdeep: 6144:ouIlWqB+ihabs7Ch9KwyF5LeLodp2D1Mmakda0qLMw7Z04P3dkJHj:T6Wq4aaE6KwyF5L0Y2D1PqL/Ft0Hj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

MemScan:Backdoor.Generic.755288 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004babbf1 )
DrWebBackDoor.Comet.152
CynetMalicious (score: 100)
CAT-QuickHealTrojan.BlockerRI.S17616033
ALYacMemScan:Backdoor.Generic.755288
ZillyaDropper.Generic.Win32.3478
AlibabaRansom:VBS/Blocker.b1ff8214
K7GWTrojan ( 004babbf1 )
Cybereasonmalicious.168040
BaiduMulti.Threats.InArchive
CyrenW32/FakeDoc.G.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Remcos-9846521-0
KasperskyTrojan-Ransom.Win32.Blocker.hrft
BitDefenderMemScan:Backdoor.Generic.755288
NANO-AntivirusTrojan.Script.Autoit.debvea
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanMemScan:Backdoor.Generic.755288
TencentWin32.Trojan.Blocker.Ecac
Ad-AwareMemScan:Backdoor.Generic.755288
SophosMal/Generic-S
ComodoMalware@#2cybsqa7u0edu
BitDefenderThetaAI:Packer.DFD329EB15
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroCryp_Embed4
McAfee-GW-EditionBehavesLike.Win32.Injector.gc
FireEyeMemScan:Backdoor.Generic.755288
EmsisoftMemScan:Backdoor.Generic.755288 (B)
JiangminTrojan.Script.wpy
AviraDR/AutoIt.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitBackdoor.Generic.DB8658
AegisLabTrojan.Win32.Genome.linK
GDataMemScan:Backdoor.Generic.755288
AhnLab-V3Trojan/Win32.Zbot.R103557
McAfeeArtemis!FA0AB9C16804
MAXmalware (ai score=99)
VBA32Hoax.Blocker
TrendMicro-HouseCallCryp_Embed4
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!N71EllaXIy8
IkarusBackdoor.Win32.SuspectCRC
MaxSecureTrojan.Autoit.AZA
FortinetW32/Dropper.PYN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MemScan:Backdoor.Generic.755288?

MemScan:Backdoor.Generic.755288 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment