Backdoor

Should I remove “Backdoor.Generic.460353”?

Malware Removal

The Backdoor.Generic.460353 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.460353 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Backdoor.Generic.460353?


File Info:

name: 9577B4CB92D0CE9BF3C5.mlw
path: /opt/CAPEv2/storage/binaries/a159ab1fe4842036a0d4aeb5de68c144f9b8aa8fc86eea59e0417ea8bc651bff
crc32: 093DC9EB
md5: 9577b4cb92d0ce9bf3c5f7e5f8a2860a
sha1: 977abe1a2ae8cbb985791468a4796fd95852c57c
sha256: a159ab1fe4842036a0d4aeb5de68c144f9b8aa8fc86eea59e0417ea8bc651bff
sha512: cb5d44428cee7500d6ecb7442e73b9350efc58ce818566b39af987fffa9e6197c661f7268c6684a4864ac11c078a602070f76d0cba8cf6a0ebbb1d95c5570220
ssdeep: 3072:7NcnCSEkBVYV0AW0olCBo4RnF1KqxlUczKyeNheYj:SnCSEkzU4EF1KKUcl6hh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3E3E01731F81F04D6693EFAB35B4B36DC788967A53990A4E36E8394D8F6EE5013806C
sha3_384: 92579561f2060424bf1f8f53e5cef8dae4c7288ecdfe2b317d896fe9e9c5861e920258b9dae9f322e8a5746c2204a2a3
ep_bytes: 60be156037018dbeebaf08ff5783cdff
timestamp: 2007-05-27 03:18:34

Version Info:

0: [No Data]

Backdoor.Generic.460353 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.26
MicroWorld-eScanBackdoor.Generic.460353
FireEyeGeneric.mg.9577b4cb92d0ce9b
ALYacBackdoor.Generic.460353
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.37443
SangforSuspicious.Win32.Save.a
AlibabaTrojanPSW:Win32/Kryptik.44d4d851
Cybereasonmalicious.b92d0c
BitDefenderThetaAI:Packer.D24168A71E
VirITTrojan.Win32.Cryptic.AZX
CyrenW32/Zbot.AU.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Kryptik.GUM
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-41735
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Generic.460353
NANO-AntivirusTrojan.Win32.Zbot.bvwvqy
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Htbz
Ad-AwareBackdoor.Generic.460353
SophosMal/Generic-R + Mal/Zbot-U
ComodoMalCrypt.Indus!@1qrzi1
VIPREPacked.Win32.Zbot.gen.y.7 (v)
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
EmsisoftMemScan:Backdoor.Generic.460353 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataBackdoor.Generic.460353
JiangminTrojan/Generic.bewv
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.18647C4
ViRobotTrojan.Win32.A.Zbot.153088.HU[UPX]
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R37324
McAfeePWS-Zbot.gen.pp
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!jAQEp+U3/d0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.U!tr
AVGWin32:Malware-gen
PandaGeneric Malware

How to remove Backdoor.Generic.460353?

Backdoor.Generic.460353 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment