Backdoor

Backdoor.Bot.159558 removal

Malware Removal

The Backdoor.Bot.159558 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.159558 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Created a process from a suspicious location
  • Creates a hidden or system file
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor.Bot.159558?


File Info:

name: 473E008A86611347621B.mlw
path: /opt/CAPEv2/storage/binaries/c63556a629dcf7960c38d18a00050a408157f309d7ddfa2278b619e8884e3793
crc32: B70F275B
md5: 473e008a86611347621bcfa17cb56cea
sha1: 3fe9ebabf44dbaac0a03a29212193140eb19015a
sha256: c63556a629dcf7960c38d18a00050a408157f309d7ddfa2278b619e8884e3793
sha512: 1fd46357d190e7d89da72bb16891dbe0cac5000526248aa2de4d7d1e7cd99a800ccb535e9cd1af0593a25299c732c0184698c2b37a6dc7e9b97a5058d3b422bd
ssdeep: 6144:fLCVGJcKgEz7QYV/hcnAptNU3Rwd+7bqJAkrayVG8:fLCVLEz75/9ptGyCbqJUyp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED749E2EA7B1AEBDC8112FF60A00A517C619D0F5D32B426F83C4A7807F3E5726527D66
sha3_384: 0d4c59c0c53190df28bf75a2a61c4395694f468f089321737b128aeb2f6d2dc839a8114b22972b1f85ee7bceb9c0017e
ep_bytes: 5589e583ec08c7042402000000ff153c
timestamp: 2012-08-26 06:54:04

Version Info:

CompanyName:
FileVersion:
FileDescription:
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x045e 0x04e4

Backdoor.Bot.159558 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.lBIn
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Bot.159558
FireEyeGeneric.mg.473e008a86611347
CAT-QuickHealVirTool.CeeInject.A
ALYacBackdoor.Bot.159558
CylanceUnsafe
VIPRETrojan.Win32.Zbot.afu (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003eb2601 )
AlibabaTrojanSpy:Win32/EncPk.6de3f3c0
K7GWTrojan ( 003eb2601 )
Cybereasonmalicious.a86611
VirITTrojan.Win32.Panda.DZR
CyrenW32/Zbot.GH.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Zbot.AAN
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-67943
KasperskyTrojan-Spy.Win32.Zbot.erlh
BitDefenderBackdoor.Bot.159558
NANO-AntivirusTrojan.Win32.Zbot.bccbah
ViRobotTrojan.Win32.A.Zbot.256296
AvastWin32:GenMalicious-KGF [Trj]
TencentMalware.Win32.Gencirc.10b72a12
Ad-AwareBackdoor.Bot.159558
EmsisoftBackdoor.Bot.159558 (B)
ComodoTrojWare.Win32.Agent.KDFK@4qfvey
DrWebTrojan.PWS.Panda.2695
ZillyaTrojan.Zbot.Win32.73481
TrendMicroTSPY_CEEINJECT_BK083DEA.TOMC
McAfee-GW-EditionBehavesLike.Win32.ZBot.fc
SophosMal/Generic-R + Mal/EncPk-AGE
IkarusVirus.Win32.CeeInject
GDataBackdoor.Bot.159558
JiangminTrojanSpy.Zbot.cbes
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen2
KingsoftWin32.Troj.Zbot.(kcloud)
ArcabitBackdoor.Bot.D26F46
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
ZoneAlarmTrojan-Spy.Win32.Zbot.erlh
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R34286
Acronissuspicious
McAfeePWS-Zbot.gen.alg
MAXmalware (ai score=99)
VBA32BScope.TrojanPSW.Papras
TrendMicro-HouseCallTSPY_CEEINJECT_BK083DEA.TOMC
RisingTrojan.Injector!1.6572 (RDMK:cmRtazpKanwoWwvUaomQpF7jDG5w)
YandexTrojan.GenAsa!0dzHmaEyNak
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4401762.susgen
FortinetW32/Zbot.AMX!tr
BitDefenderThetaGen:NN.ZexaF.34212.vy1@aircsuii
AVGWin32:GenMalicious-KGF [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Bot.159558?

Backdoor.Bot.159558 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment