Backdoor

Backdoor.Bot.151100 (file analysis)

Malware Removal

The Backdoor.Bot.151100 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.151100 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Bot.151100?


File Info:

crc32: A90D2AF1
md5: b31018d28f0dabd93d8fb4a3e96359ef
name: B31018D28F0DABD93D8FB4A3E96359EF.mlw
sha1: 3c8bfc27bd5e10ddd130eb4d424ed7b90c2743c3
sha256: 23a57ff68ecb4fdd6817806cbdde9a308423b0ed2fa1361edf7887d3f9ac0a84
sha512: 1c602636de9e0c4d9c9c82c7a36c69d9ff230242f31b1cd40721f86a4cc213c7af6cf07c613fc6f3deccedb15359b5bb5e79451d11a6e6819a17ea7300c94d9c
ssdeep: 6144:9m4e+R3Qk2XUD4RqkCbpimeyDRcmDQEOOSYq8O:9Mk2LqkCFi7schE1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Site Mile Scorch Picky 2004-2005
InternalName: Henry Unite Whim Rout
FileVersion: 10.1
CompanyName: IBM Corp.
ProductName: Ozone Care Soda
ProductVersion: 10.1
FileDescription: Smirk Nancy Israel Bard Zeke
OriginalFilename: Rabbi.exe
Translation: 0x0409 0x04b0

Backdoor.Bot.151100 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3db1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacBackdoor.Bot.151100
CylanceUnsafe
ZillyaTrojan.Spy.Win32.511
SangforTrojan.Win32.MalOb.IF
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/BScope.4c3fe392
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.28f0da
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
AvastWin32:MalOb-IF [Cryp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Bot.151100
NANO-AntivirusTrojan.Win32.MlwGen.eiabxj
MicroWorld-eScanBackdoor.Bot.151100
TencentMalware.Win32.Gencirc.114bf565
Ad-AwareBackdoor.Bot.151100
SophosML/PE-A + Troj/Agent-VSS
ComodoTrojWare.Win32.ZBot.ABKS@4lo2p9
BitDefenderThetaGen:NN.ZexaF.34294.ou0@a82MMQpi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.SMES
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
FireEyeGeneric.mg.b31018d28f0dabd9
EmsisoftBackdoor.Bot.151100 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen2
eGambitGeneric.PSW
Antiy-AVLTrojan/Generic.ASMalwS.32F148
MicrosoftPWS:Win32/Zbot!ml
ArcabitBackdoor.Bot.D24E3C
GDataBackdoor.Bot.151100
Acronissuspicious
McAfeePWS-Zbot.gen.aza
MAXmalware (ai score=99)
VBA32BScope.Trojan.Cloxer
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_ZBOT.SMES
RisingTrojan.Generic@ML.90 (RDML:/VcsLM1GryCOUK0cRq2URA)
YandexTrojan.GenAsa!ABcYkWZnxXM
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bredo.Q!tr
AVGWin32:MalOb-IF [Cryp]
Paloaltogeneric.ml

How to remove Backdoor.Bot.151100?

Backdoor.Bot.151100 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment