Backdoor Trojan

Should I remove “Trojan.Backdoor2.dmHfaSi8Fnb”?

Malware Removal

The Trojan.Backdoor2.dmHfaSi8Fnb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Backdoor2.dmHfaSi8Fnb virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Backdoor2.dmHfaSi8Fnb?


File Info:

crc32: 3F8D482A
md5: 0c23ce61e9c0f4b8e2f3dc4e03707a01
name: 0C23CE61E9C0F4B8E2F3DC4E03707A01.mlw
sha1: c78dc094525c36779ccb158f63d9f64b02d229e8
sha256: da23cc7fc7557cfeed149324132412e3ab39c804efd900551d7ed1a2f6d65ff6
sha512: c88b43421b0c7074578e19cb17591e9dbdfb4dc574dff21f103ed646bb859e718531a6fcffb53d6edf658d092e153fa9775f5650474dd4617ba1458f70dec62a
ssdeep: 1536:A2n8MU2shhcrEeU1sTQWPBrscCW1UlJpu6g485:B8MUPhJBe8WZBCJ86V85
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Backdoor2.dmHfaSi8Fnb also known as:

K7AntiVirusTrojan ( 004cc6071 )
LionicTrojan.Win32.Agent.l8Nm
Elasticmalicious (high confidence)
DrWebBackDoor.Nethief.146
CynetMalicious (score: 100)
ALYacGen:Trojan.Backdoor2.dmHfaSi8Fnb
CylanceUnsafe
ZillyaBackdoor.Agent.Win32.12958
SangforTrojan.Win32.Small.BI
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaBackdoor:Win32/Nethief.66604557
K7GWTrojan ( 004cc6071 )
Cybereasonmalicious.1e9c0f
BaiduWin32.Trojan.Agent.fm
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Nethief.NAU
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-111387
KasperskyBackdoor.Win32.Agent.tvj
BitDefenderGen:Trojan.Backdoor2.dmHfaSi8Fnb
NANO-AntivirusTrojan.Win32.Agent.qxsk
ViRobotBackdoor.Win32.Agent.56414
MicroWorld-eScanGen:Trojan.Backdoor2.dmHfaSi8Fnb
TencentWin32.Backdoor.Agent.Fhz
Ad-AwareGen:Trojan.Backdoor2.dmHfaSi8Fnb
SophosMal/Behav-044
ComodoBackdoor.Win32.Agent.~dy022@1xbots
BitDefenderThetaGen:NN.ZexaF.34236.dmHfaSi8Fnb
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_AGENT.SMEP
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.0c23ce61e9c0f4b8
EmsisoftGen:Trojan.Backdoor2.dmHfaSi8Fnb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agent.aluz
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1126976
Antiy-AVLTrojan/Generic.ASMalwS.43252
KingsoftWin32.Hack.Agent.t.(kcloud)
MicrosoftTrojan:Win32/Occamy.CDA
ZoneAlarmBackdoor.Win32.Agent.tvj
GDataGen:Trojan.Backdoor2.dmHfaSi8Fnb
AhnLab-V3Trojan/Win32.Agent.C53211
McAfeegeneric!bg.ftt
MAXmalware (ai score=100)
VBA32Backdoor.Agent
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_AGENT.SMEP
RisingBackdoor.Win32.Agent.yqo (CLASSIC)
YandexTrojan.GenAsa!tddpxThDtL8
IkarusVirus.Win32.Nethief.Y
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bdoor.TW!tr.bdr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Backdoor2.dmHfaSi8Fnb?

Trojan.Backdoor2.dmHfaSi8Fnb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment