Backdoor

Backdoor.Bot.137167 removal

Malware Removal

The Backdoor.Bot.137167 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.137167 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Bot.137167?


File Info:

name: 9DA3FC74FC5E357140B4.mlw
path: /opt/CAPEv2/storage/binaries/fbc2067a2173b333122df4b04753a4c20b69b76ba6ee79ad9f38e8174eca26d4
crc32: 23D97740
md5: 9da3fc74fc5e357140b4b632147d9aba
sha1: 3e264393cce88b593e6cb23d2321dc1c9803b9c5
sha256: fbc2067a2173b333122df4b04753a4c20b69b76ba6ee79ad9f38e8174eca26d4
sha512: fa3a6301bbfcbc7552a16dbba7e403a619c869d7a74c21cfc889f88942c5c8136b95b1fd4bbc8307bc61d986f6bd4ece08fc60ba19d1e4a0edea1a6c385a713d
ssdeep: 1536:qexlz3iP7Mvw155Pn5b5d5uxfqJUGrNrUw1+8SIj5nmtI5b1UsJR9b9ghzC7fVIj:FT3i4kP5bXcQJUeNrMbIjdaI5JTmcI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117D3E10371E42F01C6263EBB364B4A77DC4DC877942AA4E4E76E9252DAE6F91052E07C
sha3_384: 460053e026292d6085073caab9ebf74de3c08b7cf7480eb02544424423dbd751c226203814e02e2d24398ea50cf7f7da
ep_bytes: 60be154033018dbeebcf0cff5783cdff
timestamp: 2006-07-31 19:23:31

Version Info:

0: [No Data]

Backdoor.Bot.137167 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.387
MicroWorld-eScanBackdoor.Bot.137167
FireEyeGeneric.mg.9da3fc74fc5e3571
ALYacBackdoor.Bot.137167
CylanceUnsafe
VIPREPacked.Win32.Zbot.gen.y.7 (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001760f21 )
AlibabaTrojanPSW:Win32/Kryptik.f476619d
K7GWTrojan ( 001760f21 )
Cybereasonmalicious.4fc5e3
BitDefenderThetaAI:Packer.262B96BE1E
VirITTrojan.Win32.Generic.ACGC
CyrenW32/Zbot.AU.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Kryptik.HBMX
TrendMicro-HouseCallTSPY_ZBOT.WVJ
ClamAVWin.Trojan.Zbot-14582
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Bot.137167
NANO-AntivirusTrojan.Win32.Panda.crtgk
ViRobotTrojan.Win32.A.Zbot.140800.AE[UPX]
AvastFileRepMalware
TencentWin32.Trojan.Zbot.Kush
Ad-AwareBackdoor.Bot.137167
EmsisoftMemScan:Backdoor.Bot.137167 (B)
ComodoMalCrypt.Indus!@1qrzi1
ZillyaTrojan.Zbot.Win32.51697
TrendMicroTSPY_ZBOT.WVJ
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
SophosML/PE-A + Mal/Zbot-U
IkarusTrojan-Spy.Win32.Zbot
GDataBackdoor.Bot.137167
JiangminTrojanSpy.Zbot.anhr
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.44586C
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R32084
McAfeePWS-Zbot.gen.pp
VBA32BScope.Trojan-Dropper.Injector
APEXMalicious
RisingTrojan.Toga!8.136D (CLOUD)
YandexTrojan.GenAsa!KBErIPZ16lw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.U!tr
AVGFileRepMalware
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Backdoor.Bot.137167?

Backdoor.Bot.137167 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment