Backdoor

Backdoor.Bancodor information

Malware Removal

The Backdoor.Bancodor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bancodor virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Bancodor?


File Info:

name: 4D95E30759CFFF07B41A.mlw
path: /opt/CAPEv2/storage/binaries/77eb6bcbdeb63aec3f60fc433ab36b151d039503f400abd7c1bce8596342e1da
crc32: AAAF7361
md5: 4d95e30759cfff07b41a479f6606c7dd
sha1: 8f7f3a17a5f8f8b271ca7e023b39903a451db55a
sha256: 77eb6bcbdeb63aec3f60fc433ab36b151d039503f400abd7c1bce8596342e1da
sha512: 43771669bb992334934052e47db4ad22adf5328c86edde22b1e5ef5f359ffae86ae2d89b5bde038887383d70be7c93af2e3bf49be2551d82f4d4d2849ee8191c
ssdeep: 12288:vGrbgTTAqhZmKYYAxYTXAvubO8reMngT66imlsVATXUR:vZTkqjJYRxYEvUen66imlpTc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0A412223D82E0F1F63A467482EB6AFF57488965C1639338CBCC9A54ED33E94652F1C5
sha3_384: 7708ffe309a84e0f8ff9c226ea5f7f312b8092ea757eca369304d91752363cd5c78c35daaeecc60a5c5ee1c651f497ea
ep_bytes: 5589e583ec08c7042401000000ff1588
timestamp: 2010-07-01 05:39:52

Version Info:

FileDescription: Protected Application
FileVersion: 1, 0, 0, 1
ProductVersion: 1, 0, 0, 1
Comments: Is protected with Teggo MoleBox 4.3029
Translation: 0x0000 0x04b0

Backdoor.Bancodor also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lmem
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.4d95e30759cfff07
McAfeeArtemis!4D95E30759CF
MalwarebytesTrojan.MalPack.Generic
VIPREGen:Trojan.Heur2.JP.CC3@aewu!q
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00198b121 )
AlibabaPacked:Win32/MoleboxVS.190110
K7GWTrojan ( 00198b121 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D400A07A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.MoleboxVS.A suspicious
APEXMalicious
ClamAVWin.Trojan.Barys-6957974-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.67149946
NANO-AntivirusTrojan.Win32.Bifrose.ilgqc
MicroWorld-eScanTrojan.GenericKD.67149946
AvastWin32:Crypt-KEB [Drp]
TencentWin32.Backdoor.Agent.Pqil
EmsisoftTrojan.GenericKD.67149946 (B)
F-SecureBackdoor.BDS/Agent.1035083
DrWebBackDoor.Cybergate.1461
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosMal/Generic-S
JiangminBackdoor/Bancodor.cu
AviraBDS/Agent.1035083
Antiy-AVLTrojan/Win32.SGeneric
XcitiumMalware@#3k1z97vin8y93
MicrosoftTrojan:Win32/Dynamer!dtc
ViRobotTrojan.Win32.A.Refroso.47616.A
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.67149946
BitDefenderThetaAI:Packer.1AA97E641E
ALYacGen:Trojan.Heur2.JP.CC3@aewu!q
MAXmalware (ai score=89)
VBA32Backdoor.Bancodor
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CEL23
RisingTrojan.Ymacco!8.11BE1 (TFE:5:32EdQn1VgtG)
YandexTrojan.GenAsa!PZOS3iX6VhI
IkarusTrojan.Win32.Refroso
AVGWin32:Crypt-KEB [Drp]
Cybereasonmalicious.759cff
DeepInstinctMALICIOUS

How to remove Backdoor.Bancodor?

Backdoor.Bancodor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment