Backdoor

Backdoor.BotOS removal

Malware Removal

The Backdoor.BotOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.BotOS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.BotOS?


File Info:

crc32: 8DDFEE85
md5: d2b3cbabd2722e495f860d09cbc9b406
name: bob1609burkinafas2cr9.exe
sha1: da2fc212800efd721213c0c10f3dc44a69f62c19
sha256: dc4d3905716f82597e9d17a1bc5549bfbd4e96c95ac158fe5f5055bcf955c5d1
sha512: 9977d1c9cbc45615c2a394ed9c2c7276cfcd5ebae4779ea1f02c5068334f922063dafeff5134f1bf677fb3ff497f5d27376555996d5c7232b604dbe2ca20dbc1
ssdeep: 12288:7yH3nTIiJ39d/VGpGxiF43mofiJdtGJ6joTr4xbDC8uYvwguUNtO3GAp5K2JY:7yXnTD/CGUFymdrs60TrhYvwuO2Qw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Warmsun Holding 2016 All rights reserved.
InternalName: Nsfw Minute
FileVersion: 7.5.7.798
CompanyName: Warmsun Holding
PrivateBuild: 7.5.7.798
ProductName: Nsfw Minute
ProductVersion: 7.5.7.798
FileDescription: Wsid Currentconnectioncountthe Gcr Striketrhough Whiteside
OriginalFilename: Nsfw Minute
Translation: 0x0409 0x04b0

Backdoor.BotOS also known as:

MicroWorld-eScanTrojan.GenericKD.41773744
FireEyeGeneric.mg.d2b3cbabd2722e49
McAfeeRDN/Generic PWS.vo
ALYacTrojan.GenericKD.41773744
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1155053
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.41773744
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.41773744
KasperskyTrojan-PSW.Win32.Vidar.avu
AlibabaTrojanPSW:Win32/Vidar.23269cf8
NANO-AntivirusTrojan.Win32.Vidar.gafaum
RisingTrojan.Kryptik!8.8 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1045840
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
EmsisoftTrojan.GenericKD.41773744 (B)
IkarusTrojan.MSIL.Agent
JiangminTrojan.PSW.Vidar.gv
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1045840
ArcabitTrojan.Generic.D27D6AB0
ZoneAlarmTrojan-PSW.Win32.Vidar.avu
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C3473309
VBA32BScope.Adware.Wajam
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.41773744
MalwarebytesBackdoor.BotOS
PandaTrj/CI.A
ESET-NOD32MSIL/Agent.TIN
TencentWin32.Trojan-qqpass.Qqrob.Wrgd
YandexTrojan.PWS.Vidar!
MaxSecureTrojan.Malware.74562254.susgen
FortinetW32/Kryptik.GVSM!tr
BitDefenderThetaGen:NN.ZexaF.34090.Xq0@aeZK00pi
AVGWin32:Trojan-gen
Qihoo-360Win32/Trojan.PSW.0b1

How to remove Backdoor.BotOS?

Backdoor.BotOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment