Backdoor

Backdoor.Generic.468837 (B) removal guide

Malware Removal

The Backdoor.Generic.468837 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.468837 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Generic.468837 (B)?


File Info:

name: AC26236D0A15774D2CDB.mlw
path: /opt/CAPEv2/storage/binaries/909baac3b719d3340e24ee052a41c1f052f5643b11af8664cfe2afe1376fd79e
crc32: EC7C5795
md5: ac26236d0a15774d2cdb9d2012a3e077
sha1: aff86f820ab04ebc7b3bad419d0fa38c30454d18
sha256: 909baac3b719d3340e24ee052a41c1f052f5643b11af8664cfe2afe1376fd79e
sha512: 7f21b5af7c0c1e8419de6d6a86fae78418bcfcf51021b9bd4b1dcd8580cfb37a56f7edb25859c837aa32c240e1f8a6dbf6bab04043c7e15b55fbf3fe8fbf6b10
ssdeep: 3072:El4HS7CR8Nqdu50fSq9MU2P8kSevtgVPlgYE/DZU:ElluqOuWfSO6SevtQPlgD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F24D026C2438CB7C0991AB35DD7369CBF27164843051F27218F992A29D1BBD7B2DB89
sha3_384: c372c75a517e31a85c4bb45d6eb9cfb8b4a11fe4e34e0fce7fefa5a660e82c3572bd6df753a7c122ef3bdc0ea2310e46
ep_bytes: 683468000050ff75fc68435348006848
timestamp: 2007-07-04 03:06:03

Version Info:

0: [No Data]

Backdoor.Generic.468837 (B) also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.Krap.x!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.10816
MicroWorld-eScanBackdoor.Generic.468837
FireEyeGeneric.mg.ac26236d0a15774d
McAfeeArtemis!AC26236D0A15
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.881505
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001a22bb1 )
AlibabaTrojanPSW:Win32/Kryptik.9ed1dbcc
K7GWTrojan ( 001a22bb1 )
Cybereasonmalicious.d0a157
BitDefenderThetaAI:Packer.A76965561F
VirITTrojan.Win32.Panda.QAA
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBMX
TrendMicro-HouseCallMal_Zvrek3
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1282
KasperskyPacked.Win32.Krap.ae
BitDefenderBackdoor.Generic.468837
NANO-AntivirusTrojan.Win32.Krap.efeaup
AvastWin32:Cybota [Trj]
TencentWin32.Packed.Krap.Lmug
Ad-AwareBackdoor.Generic.468837
SophosML/PE-A + Mal/Zbot-U
ComodoMalCrypt.Indus!@1qrzi1
VIPREPacked.Win32.Zbot.gen.y.7 (v)
TrendMicroMal_Zvrek3
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dt
EmsisoftBackdoor.Generic.468837 (B)
SentinelOneStatic AI – Malicious PE
GDataBackdoor.Generic.468837
JiangminTrojan/Agent.eeyy
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1847F5C
ArcabitBackdoor.Generic.D72765
ZoneAlarmPacked.Win32.Krap.ae
MicrosoftPWS:Win32/Zbot.gen!Y
CynetMalicious (score: 100)
Acronissuspicious
ALYacBackdoor.Generic.468837
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingTrojan.Crypto!8.364 (CLOUD)
YandexTrojan.Kryptik!QWH4H1prYYg
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.U!tr
AVGWin32:Cybota [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Generic.468837 (B)?

Backdoor.Generic.468837 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment