Backdoor

Backdoor.Generic.580665 information

Malware Removal

The Backdoor.Generic.580665 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Generic.580665 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Backdoor.Generic.580665?


File Info:

name: 937955B4DF36B735BE29.mlw
path: /opt/CAPEv2/storage/binaries/28df4883f4a4ba4a8638dc35c73318599a9057a6ec014d94b4bff22a6ccdc977
crc32: 5E4D43C9
md5: 937955b4df36b735be29d2efe0950bdf
sha1: 8831e363d3a92d51e9e65cca190ece2bc33f14b3
sha256: 28df4883f4a4ba4a8638dc35c73318599a9057a6ec014d94b4bff22a6ccdc977
sha512: 501b0a0a7c70f7de3a81b389e4be389e8f2d6d55b970b07f9b12ce0cfbb70fd0cee6ea7107dd0f09f54ae85498f8f7cc0280e763767570066d51f94e6a1b48a8
ssdeep: 49152:h8xE8TeMrKUKitCjsMnvCJ7hK8ZRsAX9CmyI8Ur/KpRFAwah5GcE0bnjI:hhSrKUZtCjXoI/myIVipRFAwuk0I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139B5330713F6D2A9FE5B0C796E5D8A25E20DFD5E638494980E97806D79270E08E8BDCC
sha3_384: d0d9384afe46544bd053eb838bae40fb84f2d89bc8034f07ab56b7df893290860ca72af76f732fcc8b443ff853e4a696
ep_bytes: 60be00004d008dbe0010f3ff57eb0b90
timestamp: 2008-02-12 10:49:02

Version Info:

CompanyName: Eper1 Software
FileDescription: Eper1 Internet Browser
FileVersion: 1190
InternalName: Eper1
LegalCopyright: Copyright © Eper1 Software 1995-2011
OriginalFilename: Eper1.exe
ProductName: Eper1 Internet Browser
ProductVersion: 11.01
Translation: 0x0409 0x04b0

Backdoor.Generic.580665 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.937955b4df36b735
McAfeeArtemis!937955B4DF36
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.34704
SangforTrojan.Win32.Generic.ky
AlibabaVirTool:Win32/Obfuscator.21e27fbb
Cybereasonmalicious.4df36b
BitDefenderThetaGen:NN.ZexaF.34212.uoNfamccU0mc
VirITTrojan.Win32.Generic.LTV
CyrenW32/Sefnit.G.gen!Eldorado
SymantecTrojan.ADH
ESET-NOD32a variant of Win32/Kryptik.KSF
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1279
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Generic.580665
NANO-AntivirusTrojan.Win32.Zbot.cvjhcv
MicroWorld-eScanBackdoor.Generic.580665
AvastWin32:Renos-TR [Drp]
TencentMalware.Win32.Gencirc.114b6216
Ad-AwareBackdoor.Generic.580665
SophosMal/Generic-S + Mal/Zbot-CX
ComodoMalware@#1d4f55oz8jla
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Packed.21467
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_KOLAB.SMB
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
EmsisoftBackdoor.Generic.580665 (B)
SentinelOneStatic AI – Malicious PE
GDataBackdoor.Generic.580665
JiangminTrojanSpy.Zbot.ctti
eGambitUnsafe.AI_Score_83%
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Troj.Pincav.ba.(kcloud)
ArcabitBackdoor.Generic.D8DC39
ViRobotTrojan.Win32.A.Zbot.927232[UPX]
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win32.Renos.R3026
VBA32Trojan.Zeus.EA.0999
ALYacBackdoor.Generic.580665
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallWORM_KOLAB.SMB
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!mb01Yk1iMDY
IkarusTrojan.Win32.Sefnit
MaxSecureTrojan.Malware.1699151.susgen
FortinetW32/Kryptik.NAS!tr
WebrootW32.Malware.Gen
AVGWin32:Renos-TR [Drp]
PandaBck/Qbot.AO

How to remove Backdoor.Generic.580665?

Backdoor.Generic.580665 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment