Backdoor

VHO:Backdoor.MSIL.DcRat malicious file

Malware Removal

The VHO:Backdoor.MSIL.DcRat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Backdoor.MSIL.DcRat virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine VHO:Backdoor.MSIL.DcRat?


File Info:

name: 7A86C1E91C4DE8134AD4.mlw
path: /opt/CAPEv2/storage/binaries/3a8319318527c04dbca76ea473a452a0cf95a700a9a140e2fa880ce6a998c513
crc32: 4B03E99E
md5: 7a86c1e91c4de8134ad4941ffc423b7a
sha1: 1be8f58dfeca48d67cb58c80d238038b86e26d4f
sha256: 3a8319318527c04dbca76ea473a452a0cf95a700a9a140e2fa880ce6a998c513
sha512: 12f45c3f9de9d8537b232cabd1503bd0ffcaa338868d57210aca1c1a7e14f897f58a75079ad061264b185136daf2ea5e1f838a54c6b0fc02e81b7045d7480bbf
ssdeep: 24576:EzzGgn4DFRawP6Xs+2/PJuA/vE26wSjl4wS+H2Pbe:EzzGgQRaA7/PMANXSpzy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8556B027E44CE02F0092733C2EF458897B4A95176A6E72B7DBA376D65123A73D0D9CB
sha3_384: cc0b45732db3f3031a73115bc02d9d8eb222a23dcb44de3a6e602f3a93981515c8a05e2b1a9dc63e9a097a26a0f7973b
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-09 21:26:22

Version Info:

FileVersion: 5.15.2.0
OriginalFilename: libGLESv2.dll
ProductName: libGLESv2
ProductVersion: 5.15.2.0
Translation: 0x0409 0x04b0

VHO:Backdoor.MSIL.DcRat also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILMamut.1308
ALYacIL:Trojan.MSILMamut.1308
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWSpyware ( 0058ebd51 )
K7AntiVirusSpyware ( 0058ebd51 )
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Spy.Agent.DTP
APEXMalicious
KasperskyVHO:Backdoor.MSIL.DcRat.gen
BitDefenderIL:Trojan.MSILMamut.1308
AvastWin32:RATX-gen [Trj]
Ad-AwareIL:Trojan.MSILMamut.1308
EmsisoftIL:Trojan.MSILMamut.1308 (B)
DrWebTrojan.PWS.StealerNET.124
McAfee-GW-EditionTrojan-FUJL!7A86C1E91C4D
FireEyeGeneric.mg.7a86c1e91c4de813
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1249330
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitIL:Trojan.MSILMamut.D51C
GDataIL:Trojan.MSILMamut.1308
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUJL.C5119684
Acronissuspicious
McAfeeTrojan-FUJL!7A86C1E91C4D
MAXmalware (ai score=88)
MalwarebytesMalware.AI.2331960520
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DVA!tr
BitDefenderThetaGen:NN.ZemsilF.34712.or0@aK15lopi
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.dfeca4

How to remove VHO:Backdoor.MSIL.DcRat?

VHO:Backdoor.MSIL.DcRat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment