Backdoor

What is “Backdoor.Win32.Rbot.krv”?

Malware Removal

The Backdoor.Win32.Rbot.krv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Rbot.krv virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Rbot.krv?


File Info:

name: 6DA4B246B939071F5936.mlw
path: /opt/CAPEv2/storage/binaries/e028c7b6891fa1c19505e7f42296ca3b61f20503f3e0917103bbf64d47b10c70
crc32: 05B5B620
md5: 6da4b246b939071f59365af4c18f65f5
sha1: 9342a7153b1bac0f29deb648ef4ab9e5b7f7e960
sha256: e028c7b6891fa1c19505e7f42296ca3b61f20503f3e0917103bbf64d47b10c70
sha512: 2e420f2c31b3bb02e65c6cf7d9c8dd041c43099c24f8536f2ee57ee8af04c79ade633aac91709c3074117d92a6470ed3d44ab47b34281099b451ecdf843fea50
ssdeep: 12288:mb5v4B8DETY/DHqk1tQamtbcGqgpwdygZZ6dt65OWgET:eoT+DHqcSamxqmgZZat6YK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BA423549138342BFE15E47D620A0CBD391E9B47C87249437A9FAD02A84247F5BFCA7B
sha3_384: 1e6ac538c3d12d945df9361f788678ff85608b8bd41f1375a44621df6177ca0dbde9584f9f7d6b0740e6db3effaed1be
ep_bytes: 558bec83c4f0b800104000e801000000
timestamp: 2009-01-28 16:30:24

Version Info:

0: [No Data]

Backdoor.Win32.Rbot.krv also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Rbot.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.6da4b246b939071f
McAfeeRDN/Sdbot.worm
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaBackdoor:Win32/Sdbot.8c991672
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_80% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Rbot.krv
BitDefenderTrojan.GenericKD.38228179
MicroWorld-eScanTrojan.GenericKD.38228179
AvastWin32:Malware-gen
TencentWin32.Backdoor.Rbot.Wski
Ad-AwareTrojan.GenericKD.38228179
EmsisoftTrojan.GenericKD.38228179 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosGeneric PUA JD (PUA)
IkarusBackdoor.Rbot
eGambitUnsafe.AI_Score_92%
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.C669
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.38228179
AhnLab-V3Backdoor/Win.Rbot.C4826157
Acronissuspicious
ALYacTrojan.GenericKD.38228179
MAXmalware (ai score=88)
VBA32TScope.Malware-Cryptor.SB
TrendMicro-HouseCallTROJ_GEN.R002H06L821
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Sdbot!worm
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
Cybereasonmalicious.53b1ba
PandaTrj/CI.A

How to remove Backdoor.Win32.Rbot.krv?

Backdoor.Win32.Rbot.krv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment