Backdoor

About “Backdoor.Bot.213820” infection

Malware Removal

The Backdoor.Bot.213820 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.213820 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Bot.213820?


File Info:

crc32: 5DC03F9F
md5: d8ef99f66f2aca5e6cf023f0fc1ded01
name: D8EF99F66F2ACA5E6CF023F0FC1DED01.mlw
sha1: 85a021f6b4f663a425b586ff3f774b4f0ad51fc8
sha256: 1a57877e082dd03532d02db9d4416ad01876e9e541c18dec178d714c1248c916
sha512: 329c3cdf4ef49f7ba031c7f28e6948afea4198c2ed90a9007af8343df096984931f40a3b2a0f36235e8e676b3b72e21a5cfea17350cb4040c5fea09a432458b7
ssdeep: 6144:vLtudNYOQ2uiDYpbyG4M4zLW0WkLFoltrtym0:vLEdNYF2uiEpND4PWV8Fg1Am0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1996-1998 Quarterdeck Corporation. All rights reserved worldwide
InternalName: PWREMOTE
FileVersion: 1.51
CompanyName: Quarterdeck Corporation
LegalTrademarks: Quarterdeck is a registered trademark and RapidRemote is a trademark of Quarterdeck Corporation.
ProductName: Procomm(r) RapidRemote(tm) Version 1.5
FileDescription: RapidRemote Application
OriginalFilename: PWREMOTE.EXE
Translation: 0x0409 0x04e4

Backdoor.Bot.213820 also known as:

LionicVirus.Win32.Nimnul.lse3
Elasticmalicious (high confidence)
ALYacBackdoor.Bot.213820
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Ramnit.86da5804
Cybereasonmalicious.66f2ac
BaiduWin32.Trojan.Kryptik.mx
SymantecW32.Ramnit.B!inf
ESET-NOD32a variant of Generik.ICEYBYL
APEXMalicious
AvastWin32:Ramnit-F
ClamAVWin.Virus.Ramnit-9775603-0
BitDefenderBackdoor.Bot.213820
MicroWorld-eScanBackdoor.Bot.213820
TencentWin32.Backdoor.Bot.Wurf
Ad-AwareBackdoor.Bot.213820
ComodoVirus.Win32.Ramnit.K@37eb7u
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.d8ef99f66f2aca5e
EmsisoftBackdoor.Bot.213820 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Occamy.C
GDataBackdoor.Bot.213820
AhnLab-V3Malware/Win32.Generic.C2538436
McAfeeArtemis!D8EF99F66F2A
MAXmalware (ai score=99)
PandaTrj/CI.A
IkarusWin32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Ramnit-F
Paloaltogeneric.ml

How to remove Backdoor.Bot.213820?

Backdoor.Bot.213820 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment