Backdoor

About “Backdoor.Win32.Poison.cjbb” infection

Malware Removal

The Backdoor.Win32.Poison.cjbb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Poison.cjbb virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Poison.cjbb?


File Info:

name: F86E70E87255ED133FFF.mlw
path: /opt/CAPEv2/storage/binaries/0481d2835137903e04a5f50cc632e0e80243927c7dfa9d7e5817f4973b456f81
crc32: B1AFE36A
md5: f86e70e87255ed133fffe8c5f34d4d3b
sha1: 4d6d2d3f023d3c4c049b88598d9df1539f666280
sha256: 0481d2835137903e04a5f50cc632e0e80243927c7dfa9d7e5817f4973b456f81
sha512: f8e698a284388e2071a1f7a9f703680d32ca45848516e31b8da977d8a338b2e93a9efff0f27caea58413d13d0009b0bd99bf364c5c3a3cf83c0e8ff8584c15a0
ssdeep: 6:idq2Vg3F+X32Tj4HYlOjG//AHWhIIgd3iOuB:e9GSGTsHIOjG/oOIrzuB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FCE1CD47E6956FF7C15E837711CF840A70BC34345763910A0D95417631A1B649768A4D
sha3_384: 4341aaf545f11f95a6b59593ac6bb539edced268ff75e4036b96a1b7bf8350e48099d6e8d7c5de591c217133b0148489
ep_bytes: b800044000ffd06a00e800000000ff25
timestamp: 2008-01-06 14:51:31

Version Info:

0: [No Data]

Backdoor.Win32.Poison.cjbb also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur2.FU.aiW@aCs7Tyk
SkyhighBackDoor-FABZ!F86E70E87255
McAfeeBackDoor-FABZ!F86E70E87255
K7AntiVirusTrojan ( 005325ee1 )
K7GWTrojan ( 005325ee1 )
Cybereasonmalicious.f023d3
BitDefenderThetaAI:Packer.AFF413981F
VirITBackdoor.Win32.Generic.UOG
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.24568-1
KasperskyBackdoor.Win32.Poison.cjbb
BitDefenderGen:Trojan.Heur2.FU.aiW@aCs7Tyk
AvastWin32:RATX-gen [Trj]
EmsisoftGen:Trojan.Heur2.FU.aiW@aCs7Tyk (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Poison.812
VIPREGen:Trojan.Heur2.FU.aiW@aCs7Tyk
TrendMicroTROJ_GEN.R03BC0PAL24
SophosTroj/Smalla-Gen
IkarusBackdoor.Poisonivy
JiangminBackdoor/Poison.do
VaristW32/PoisonIvy.F.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Poison.nae
XcitiumBackdoor.Win32.Poison.aec13@1d9dn8
ArcabitTrojan.Heur2.FU.E06DDC
ZoneAlarmBackdoor.Win32.Poison.cjbb
GDataGen:Trojan.Heur2.FU.aiW@aCs7Tyk
GoogleDetected
AhnLab-V3Trojan/Win32.Poison.R2018
ALYacGen:Trojan.Heur2.FU.aiW@aCs7Tyk
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0PAL24
TencentBackdoor.Win32.Poison.b
SentinelOneStatic AI – Suspicious PE
FortinetW32/Smalla.DKI!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Poison.cjbb?

Backdoor.Win32.Poison.cjbb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment