Backdoor

Backdoor.Bot.128027 information

Malware Removal

The Backdoor.Bot.128027 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.128027 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Backdoor.Bot.128027?


File Info:

name: 7681267DE8E5E8390A71.mlw
path: /opt/CAPEv2/storage/binaries/21c5f56e1935e5c3ec489b83dc5c92d72d2c23d55f157bee84ed8a81a07bec95
crc32: A7519346
md5: 7681267de8e5e8390a710134b37f0d5c
sha1: a5555e4dcd54d581a8603c75f770642d4bd28fd8
sha256: 21c5f56e1935e5c3ec489b83dc5c92d72d2c23d55f157bee84ed8a81a07bec95
sha512: e76ddcdbbac9a1c1786a11b08bc34b47bfacd67d1cf61361778ce47e1d2d1fb5405cacb566399b8760a4ac4355100acec076124838f7e1f463b07330aa67bf02
ssdeep: 1536:uvnSawBzA2l+k7NE2wV/F4gliD8aX4ztQYXKO9Iv1dHLHB7KjWoiLFKw3rLNGszE:uvSawxlj+4tzoRL9Y5HdK+RKwL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5C3AD6A7AE058B2D5B616725924773366FAFD3814389993E380FF4E2C35482633C793
sha3_384: 5c177e6ae3f3453422475014cff11f4f131dc9d341e9fc4fc34e65ca32d0d79641129bed45152a11651ac7b6a4eb434c
ep_bytes: 31c001d84389d94839c801c801d801cb
timestamp: 2009-04-10 14:15:37

Version Info:

0: [No Data]

Backdoor.Bot.128027 also known as:

LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Bot.128027
FireEyeGeneric.mg.7681267de8e5e839
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan-Spy.Win32.Zbot.gen (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001140e1 )
AlibabaTrojanSpy:Win32/VirusConstructor.8689629a
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.de8e5e
CyrenW32/Trojan.DERF-5253
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.ACH
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-9841872-0
KasperskyTrojan-Spy.Win32.Zbot.adbg
BitDefenderBackdoor.Bot.128027
NANO-AntivirusTrojan.Win32.Zbot.baopn
AvastSf:Zbot-CQ [Trj]
TencentWin32.Trojan-spy.Zbot.Ahyf
Ad-AwareBackdoor.Bot.128027
EmsisoftBackdoor.Bot.128027 (B)
ComodoTrojWare.Win32.Spy.Zbot.ABW@1qnp50
DrWebVirusConstructor.Panda.2
ZillyaTrojan.Zbot.Win32.15414
TrendMicroTSPY_ZBOT.SMRL
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.Zbot
GDataBackdoor.Bot.128027
JiangminTrojanSpy.Zbot.uck
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.493658
KingsoftWin32.Heur.KVMH008.a.(kcloud)
ArcabitBackdoor.Bot.D1F41B
ZoneAlarmTrojan-Spy.Win32.Zbot.adbg
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.C48462
BitDefenderThetaAI:Packer.461280C51E
ALYacBackdoor.Bot.128027
TACHYONTrojan-Spy/W32.ZBot.119296.P
VBA32BScope.TrojanPSW.Panda
MalwarebytesMalware.AI.2217174620
TrendMicro-HouseCallTSPY_ZBOT.SMRL
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!316CAGaCemI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.ADBG!tr
AVGSf:Zbot-CQ [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Backdoor.Bot.128027?

Backdoor.Bot.128027 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment