Backdoor

How to remove “Backdoor.InfoStealer”?

Malware Removal

The Backdoor.InfoStealer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.InfoStealer virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • CAPE detected the SpyGate malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system

How to determine Backdoor.InfoStealer?


File Info:

name: 8996E7D92F3E74B3F9FE.mlw
path: /opt/CAPEv2/storage/binaries/bbcc41a76ae6fe055bf71223a9f87ede2450b9d2704fd3b7821c27450ae07d89
crc32: CB41DA8F
md5: 8996e7d92f3e74b3f9fe937dcc6a6442
sha1: 0ba551dd363317833f3edea5e1e14a617ca1fea3
sha256: bbcc41a76ae6fe055bf71223a9f87ede2450b9d2704fd3b7821c27450ae07d89
sha512: 4c3af523f649cab9567ec20af007cb850d4080de5995af247b72dbc7d961ec28742f49beb056f20df0591a5b02c2393c96c5efc8274c277afbaf38f2d7e64869
ssdeep: 1536:y/BmvftFstac0hBjkJRHXfo31bjmVeLRJwiXjO7HUEotQtGDew8Wef:y/2tfjmHXfoFGiXS7EQtGDD3e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FA34A493BD4AD21DAFE6FB90472050583B1D16F5A13EB8E1CC148E91BBBB844E436E7
sha3_384: 70317ff37162e4f6eb7e0d030e086ce9d882f43d375bb449cbaa6bc1bf2c889f1d056b3af5844e58f43c0c14f78fceea
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-15 21:56:23

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Stub.exe
LegalCopyright:
OriginalFilename: Stub.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Backdoor.InfoStealer also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
FireEyeGeneric.mg.8996e7d92f3e74b3
CAT-QuickHealBackdoor.Bladabindi.AL3
McAfeeSpyGate!8996E7D92F3E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
K7GWTrojan ( 700000121 )
Cybereasonmalicious.92f3e7
BaiduMSIL.Backdoor.Bladabindi.a
VirITTrojan.Win32.MSIL.JTO
CyrenW32/MSIL_Bladabindi.Z.gen!Eldorado
SymantecTrojan.Spygate
ESET-NOD32a variant of MSIL/Bladabindi.AT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.njRAT-7400469-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Agent.edqjjw
ViRobotTrojan.Win32.Z.Keylogger.98304.L
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
Ad-AwareGen:Heur.MSIL.Krypt.!cdmip!.2
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
ComodoTrojWare.MSIL.Keylogger.A@57jrow
DrWebTrojan.PWS.Siggen1.12069
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
SophosML/PE-A + Mal/Bladabi-O
IkarusTrojan-PWS.MSIL
JiangminTrojan/Generic.biicj
WebrootW32.Trojan.Spygate
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.A8F4
MicrosoftPWS:MSIL/Mintluks.A
GridinsoftRansom.Win32.Bladabindi.sa
SUPERAntiSpywareTrojan.Agent/Gen-Keylogger
GDataMSIL.Backdoor.Bladabindi.AV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.C228012
BitDefenderThetaGen:NN.ZemsilF.34212.gm0@a0GT!8i
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.InfoStealer
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BLADABI.SMC
TencentMalware.Win32.Gencirc.10c2b770
YandexTrojan.Agent!bLd2r/gQjv0
SentinelOneStatic AI – Malicious PE
FortinetMSIL/SpyPSW.AVQ!tr
AVGMSIL:KillAV-B [Trj]
AvastMSIL:KillAV-B [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.InfoStealer?

Backdoor.InfoStealer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment