Backdoor

Backdoor.Bot.143790 information

Malware Removal

The Backdoor.Bot.143790 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.143790 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Bot.143790?


File Info:

name: 929B5211045A83FC4155.mlw
path: /opt/CAPEv2/storage/binaries/27dc6f8e996c2c3769926f17a3e0670e0a96f5e12c6151e451e899f3b44c0656
crc32: C0160912
md5: 929b5211045a83fc41558f6b46cef2cf
sha1: 515e90d71e61900743b857dc85a0f6383f752740
sha256: 27dc6f8e996c2c3769926f17a3e0670e0a96f5e12c6151e451e899f3b44c0656
sha512: 90e95b115e547322444870e9118b8f7d81bd3ff8b9c9dd167d9377c3fcae94a68a422c0c49444f7c0c08b4ce556cf9d2b3ad18ffce0736a9f9e62ce49bb33d5b
ssdeep: 6144:6mUgOoTNajHKGRW7sxTicPwxRztjcsp2vac:6mLO4ojHKG1TicPkx54vac
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E124122A94353EBCC5232B355A4BBEF28CE8934F6A581F95E97E08F5D0786943C77002
sha3_384: eaf42e7d7dd8fc446cf2ef39396395e91273cf5eeba172402ecda00057211f891c2f3d4922019213c2feb86ab08ffe14
ep_bytes: 60be0010d2008dbe00006effc7870ce0
timestamp: 2005-03-28 02:54:12

Version Info:

0: [No Data]

Backdoor.Bot.143790 also known as:

BkavW32.MosquitoQKK.Fam.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Bot.143790
FireEyeGeneric.mg.929b5211045a83fc
McAfeeArtemis!929B5211045A
CylanceUnsafe
ZillyaTrojan.Losya.Win32.5
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaRansom:Win32/LockScreen.508a9701
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.1045a8
VirITTrojan.Win32.Winlock.EGQ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.MOS
APEXMalicious
ClamAVWin.Trojan.Losya-11
KasperskyHEUR:Trojan.Win32.Generic.Cds.a
BitDefenderBackdoor.Bot.143790
NANO-AntivirusTrojan.Win32.Kryptik.fcoeyk
AvastFileRepMalware
TencentWin32.Trojan.Falsesign.Hssh
Ad-AwareBackdoor.Bot.143790
EmsisoftBackdoor.Bot.143790 (B)
ComodoMalware@#3ihfx0bcvart3
DrWebTrojan.Winlock.2876
VIPREPacked.Win32.PWSZbot.gen (v)
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-R + Mal/EncPk-ZC
IkarusTrojan.Win32.Yakes
GDataBackdoor.Bot.143790
JiangminTrojan/Losya.al
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.65F20A
KingsoftWin32.Heur.KVMH019.a.(kcloud)
ViRobotTrojan.Win32.A.Losya.220248.A[UPX]
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/LockScreen.BA
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34212.nmHfaqAQNopc
ALYacBackdoor.Bot.143790
VBA32Trojan.Zeus.EA.0999
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1946583.susgen
FortinetW32/Generic.AC.2948285
AVGFileRepMalware
PandaGeneric Malware

How to remove Backdoor.Bot.143790?

Backdoor.Bot.143790 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment