Backdoor

Should I remove “Backdoor.Cycbot.I”?

Malware Removal

The Backdoor.Cycbot.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Cycbot.I virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:55152
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Harvests cookies for information gathering

How to determine Backdoor.Cycbot.I?


File Info:

name: 55343C060949CF7EF081.mlw
path: /opt/CAPEv2/storage/binaries/9fd74a89af5d5f6707dc0784f4a737595a7a53a5fc3895f63b9f43f98d5258f8
crc32: 47F32176
md5: 55343c060949cf7ef08169f1758b40f0
sha1: 472bef14ef90ead4c2d18a8eda48fa4db092a133
sha256: 9fd74a89af5d5f6707dc0784f4a737595a7a53a5fc3895f63b9f43f98d5258f8
sha512: 053d24cc2025bd5466b9e2854f6f212d56affab750a8f4d5cf7f360f7d2d09b05826e63d834c7a48898d1b498fdf0a5261090377227afa22c2fe645938466b2c
ssdeep: 3072:G49Kn+yAhAN9jFcbqHurFMAAwFohdGUnGWLjxIqakmqHKAz5PzSEWxHV:GsEH6ABcb7+WFoVPK3tc5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14214F1F11264A6B7E41C4E3A21F7912C7751B5ABC7941C0BEF88431F692462CEC36CE6
sha3_384: a2109902694b7988d2c86c9cdf925f57e1fc36d177844341dc42b1c039ae46d73dbeb761e01068ddc8a2f0331d43f679
ep_bytes: 558bec81eca40100006a006a006a00fc
timestamp: 2005-11-25 06:47:34

Version Info:

FileVersion: 1.0.0.5
PrivateBuild: 1468
ProductVersion: 1.0.0.5
Translation: 0x0809 0x04b0

Backdoor.Cycbot.I also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader3.10151
MicroWorld-eScanBackdoor.Cycbot.I
FireEyeGeneric.mg.55343c060949cf7e
ALYacBackdoor.Cycbot.I
ZillyaBackdoor.Gbot.Win32.1521
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 003210941 )
AlibabaBackdoor:Win32/Obfuscator.62f177a1
K7GWBackdoor ( 003210941 )
Cybereasonmalicious.60949c
BitDefenderThetaAI:Packer.3B02961514
VirITTrojan.Win32.Cryptor.A
CyrenW32/Goolbot.J.gen!Eldorado
SymantecBackdoor.Cycbot!gen3
tehtrisGeneric.Malware
ESET-NOD32Win32/Cycbot.AF
TrendMicro-HouseCallBKDR_CYCBOT.SME3
ClamAVWin.Trojan.Cycbot-5559
KasperskyBackdoor.Win32.Gbot.aiem
BitDefenderBackdoor.Cycbot.I
NANO-AntivirusTrojan.Win32.Gbot.dahhm
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
AvastWin32:Cybota [Trj]
TencentWin32.Backdoor.Gbot.Stua
Ad-AwareBackdoor.Cycbot.I
EmsisoftBackdoor.Cycbot.I (B)
ComodoTrojWare.Win32.Kryptik.OKS@3bq8rq
VIPREBackdoor.Cycbot.I
TrendMicroBKDR_CYCBOT.SME3
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/FakeAV-IS
IkarusTrojan.SuspectCRC
JiangminBackdoor/Gbot.faj
WebrootW32.Pdf.Exploit
AviraTR/Kazy.25000.72
MAXmalware (ai score=100)
MicrosoftBackdoor:Win32/Cycbot.B
ViRobotBackdoor.Win32.A.Gbot.192512.M
ZoneAlarmBackdoor.Win32.Gbot.aiem
GDataBackdoor.Cycbot.I
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4202
McAfeeBackDoor-EXI.gen.k
TACHYONBackdoor/W32.GBot.192512.C
VBA32BScope.Trojan.Zbot.2312
CylanceUnsafe
APEXMalicious
RisingTrojan.Win32.Fednu.fna (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/CYCBOT.SMI!tr.bdr
AVGWin32:Cybota [Trj]
PandaTrj/Cycbot.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Cycbot.I?

Backdoor.Cycbot.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment