Backdoor

Backdoor.Bot.39528 (file analysis)

Malware Removal

The Backdoor.Bot.39528 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.39528 virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Bot.39528?


File Info:

crc32: C275C7F4
md5: 4c9903e86d5e2896d00ff2b7f57f5363
name: 4C9903E86D5E2896D00FF2B7F57F5363.mlw
sha1: fa0d19d8fdefec2487f7b4437206450fa89ad9cb
sha256: 8c786ac8501c2c4d3815551e8a76c49d7d0905249264a1e46c14a6ef9315f8d4
sha512: 43cdf2a88797182f0dc4c69e9b9c99dc297162aaea0f55f7914daa8966035658250b38e7e3369ee7b3610f3a3f44cca569210ff356a8d3ddc167871c7b52bc36
ssdeep: 24576:C/gF780FsaZh5N5ub0CsaPwF5doaayYVtNy+DAZi1:CYRFsaZPNFaoF1lYVtmC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Bot.39528 also known as:

LionicTrojan.Win32.Generic.4!c
ALYacBackdoor.Bot.39528
CylanceUnsafe
SangforBackdoor.Win32.Bot.39528
AlibabaBackdoor:Win32/WinKeyChanger.14a2981a
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecW32.IRCBot
APEXMalicious
AvastWin32:PUP-gen [PUP]
BitDefenderBackdoor.Bot.39528
NANO-AntivirusTrojan.Win32.AgoBot.qthrb
MicroWorld-eScanBackdoor.Bot.39528
SophosMal/Generic-S
ComodoMalware@#1l3oogdz6redt
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.38KH13
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.4c9903e86d5e2896
EmsisoftBackdoor.Bot.39528 (B)
SentinelOneStatic AI – Suspicious SFX
Antiy-AVLTrojan/Generic.ASMalwS.8CDC06
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitBackdoor.Bot.D9A68
GDataBackdoor.Bot.39528
McAfeeArtemis!4C9903E86D5E
MAXmalware (ai score=81)
VBA32Backdoor.Ursap
TrendMicro-HouseCallTROJ_SPNR.38KH13
YandexBackdoor.Ursap!DY9KQFjzdng
IkarusPUA.WinKeyChanger
FortinetW32/AgoBot.T!worm
AVGWin32:PUP-gen [PUP]
Qihoo-360Win32/Backdoor.Bot.HwYDNP8A

How to remove Backdoor.Bot.39528?

Backdoor.Bot.39528 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment