Backdoor

Backdoor:Win32/Bafruz.O (file analysis)

Malware Removal

The Backdoor:Win32/Bafruz.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bafruz.O virus can do?

  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Bafruz.O?


File Info:

crc32: 8EA38114
md5: 6ee39eaff7ce2b14eefdd841715d5eb6
name: 6EE39EAFF7CE2B14EEFDD841715D5EB6.mlw
sha1: 88b19fd1c640bd504b6b72687f37c5a993822f44
sha256: a47f966c97eb820d413c99159e8a5817f8383ad023ef7b5824d8bde0c3218938
sha512: 9a32dc1c10065df5e3d69aafde6bbfcf2bde68c66e3113a4cc76bb0d50ec388b886f5a779b1e9bede4e1a22532124734f28f4c447f8b5c4766e6a7ace4ff264c
ssdeep: 24576:uE79tpK8643KcGjBdba1X8wQFW5QCdv2fOf54eTv0rGJ:uatbKcGjBpaK62ELTv0W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Bafruz.O also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SangforTrojan.Win32.Save.a
Cybereasonmalicious.1c640b
SymantecTrojan.Gen
APEXMalicious
KasperskyTrojan-Ransom.Win32.Hexzone.jaz
AlibabaRansom:Win32/Hexzone.5cff43cc
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Ransom.Hexzone.dfl@3l1qdf
TrendMicroTROJ_DELF.WJT
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.6ee39eaff7ce2b14
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Hexzone.aos
eGambitUnsafe.AI_Score_100%
MicrosoftBackdoor:Win32/Bafruz.O
AegisLabTrojan.Win32.Hexzone.j!c
AhnLab-V3Trojan/Win32.Hexzone.C32842
McAfeeArtemis!6EE39EAFF7CE
VBA32TScope.Trojan.Delf
PandaGeneric Malware
TrendMicro-HouseCallTROJ_DELF.WJT
YandexTrojan.Hexzone!J04LTUgEnPE
IkarusTrojan-Ransom.Hexzone
MaxSecureTrojan.Malware.1735249.susgen
FortinetW32/Hexzone.JAR!tr

How to remove Backdoor:Win32/Bafruz.O?

Backdoor:Win32/Bafruz.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment