Backdoor

Should I remove “Backdoor.Bozok”?

Malware Removal

The Backdoor.Bozok is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bozok virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

myhostvav.ddns.net

How to determine Backdoor.Bozok?


File Info:

crc32: 953C2EC6
md5: 4ddb5c0d77b85cdc74e87be545514abc
name: kakaha.exe
sha1: ed3abeae8e80a09567f60e5e464621925b52c684
sha256: 717f00fd2a55904b99caea19c29a55d6ece7a66358917800f4fbb44df174a50d
sha512: 4838bb954cbdb8026d3d973a6763361b6416e3df2d8ceb621697a098c0bd24aaaec7f023178aff5c39612dbe0af98fbd4181273a03682b4832555bc4a472db5a
ssdeep: 6144:hq3/T91J9HF0p1B3pP/dme7ly39Xx6z1XGXTs1xxjicgFJPeMLgZzVkJ:8HFUdzk39X8z1XGXTsnx+cgFJPeBVg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Bozok also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Trojan.Heur.syW@Ir3DMnd
FireEyeGeneric.mg.4ddb5c0d77b85cdc
McAfeeBackDoor-FDLJ!4DDB5C0D77B8
CylanceUnsafe
VIPREBackdoor.Win32.Bezigate.a (v)
AegisLabTrojan.Win32.Boht.mgO5
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Trojan.Heur.syW@Ir3DMnd
K7GWTrojan ( 0055e3e61 )
K7AntiVirusTrojan ( 0055e3e61 )
ArcabitTrojan.Heur.ECD118C
TrendMicroTROJ_GEN.R002C0CEC20
BaiduWin32.Trojan.Delf.ag
F-ProtW32/Dropper.gen8!Maximus
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-1384832
KasperskyTrojan.Win32.Boht.aar
AlibabaBackdoor:Win32/Bezigate.f45fa3bd
NANO-AntivirusTrojan.Win32.Boht.csfbaw
TencentMalware.Win32.Gencirc.10b3cd46
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoTrojWare.Win32.Sysn.SCZ@52dp1w
F-SecureBackdoor.BDS/Hupigon.Gen
DrWebTrojan.DownLoad3.39954
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.syW@Ir3DMnd (B)
SentinelOneDFI – Malicious PE
CyrenW32/Dropper.gen8!Maximus
JiangminTrojan.Boht.fp
MaxSecureTrojan.Malware.6785526.susgen
AviraBDS/Hupigon.Gen
WebrootW32.Malware.gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Boht
ZoneAlarmTrojan.Win32.Boht.aar
AhnLab-V3Dropper/Win32.Sysn.R83515
Acronissuspicious
VBA32BScope.Trojan.Download
Ad-AwareGen:Trojan.Heur.syW@Ir3DMnd
MalwarebytesBackdoor.Bozok
PandaTrj/Genetic.gen
ESET-NOD32Win32/Delf.AAV
TrendMicro-HouseCallTROJ_GEN.R002C0CEC20
RisingBackdoor.Bezigate!8.29D (CLOUD)
YandexTrojan.Zobok.Gen.LP
IkarusTrojan-Dropper.Delf
eGambitRAT.Bozok
FortinetW32/Delf.AJG!tr
BitDefenderThetaAI:Packer.F972DB901B
AVGWin32:Malware-gen
Cybereasonmalicious.d77b85
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.BO.b6c

How to remove Backdoor.Bozok?

Backdoor.Bozok removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment