Backdoor

How to remove “Backdoor.BlackMoon”?

Malware Removal

The Backdoor.BlackMoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.BlackMoon virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.BlackMoon?


File Info:

crc32: CB58F2AD
md5: fdd02c48f6baedd65237ff493b3d150e
name: FDD02C48F6BAEDD65237FF493B3D150E.mlw
sha1: 6c6d768f94a43d29c65574994d4ad57bff0eaea4
sha256: 57adba2a7d48565123d26ecf9cd7ac7f837c6e01a94f4c59d0458ef3a8e87f87
sha512: ec8c32355407dcabee0abfe71ec9fcdcdabf659c0afa7ded191c4c2703a58015f8b86c0c24d15325fb83a6d9d54f7d47d8508159ea8a4b8c6840d7f7e441f431
ssdeep: 49152:laE/zCd2vIqkC8U7uKmVi0Dxq2WUY7CDyUBCeH1mUXs:lHCd+ILqmMwxcUYZUToU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2018-2021 x751cx54aax5c0fx6d45
FileVersion: 2.6.0.1
CompanyName: x751cx54aax5c0fx6d45
Comments: DNF SSx7eb8x5a03x5a03
ProductName: SSx7eb8x5a03x5a03
ProductVersion: 2.6.0.1
FileDescription: DNF SSx7eb8x5a03x5a03
Translation: 0x0804 0x04b0

Backdoor.BlackMoon also known as:

K7AntiVirusAdware ( 005071f51 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CylanceUnsafe
K7GWAdware ( 005071f51 )
Cybereasonmalicious.f94a43
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34266.roKfaOLg3Blb
McAfee-GW-EditionBehavesLike.Win32.Flyagent.vc
FireEyeGeneric.mg.fdd02c48f6baedd6
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.19Q2126
Acronissuspicious
McAfeeArtemis!FDD02C48F6BA
VBA32Backdoor.BlackMoon
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HALH!tr
Paloaltogeneric.ml

How to remove Backdoor.BlackMoon?

Backdoor.BlackMoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment