Backdoor

Backdoor.Win32.Saklof removal

Malware Removal

The Backdoor.Win32.Saklof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Saklof virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Backdoor.Win32.Saklof?


File Info:

name: 848652D1FC3C06E0CC07.mlw
path: /opt/CAPEv2/storage/binaries/2a1b197c196c287f82a3bddd0b4375241e00d1cc8c765250e125b23ee19256df
crc32: 78863F15
md5: 848652d1fc3c06e0cc07e0290ac0c7bc
sha1: f3f525ce0c21d6795d821cdbc5d78ac01a71a500
sha256: 2a1b197c196c287f82a3bddd0b4375241e00d1cc8c765250e125b23ee19256df
sha512: d5db89cc901c93c4372779b7c147890de0bdd6c46ea110682dc7a81c3d9feb1fe3d33e39e496f907740e272bd7246d106cf248d8959d7a7213827a57244bd81f
ssdeep: 24576:JiRTGthsqBCTo1eD3jR6ZeVIvx/Hcxt+BCgTvBHz2:JCA0d6Dx/H2GTZi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172159D33E58280F2C115253155BB573AAE74BB4A0AB5CAC79794DF792C33291EB3720E
sha3_384: 15a3cc3ab5f1835cc9687a0b6b0fb69424d2ec96ba342c1c8fda61484519de95be2bd16579f8adb2488715cd4d02afb9
ep_bytes: 558bec6aff68d0584c0068b4cb480064
timestamp: 2022-01-15 11:43:36

Version Info:

0: [No Data]

Backdoor.Win32.Saklof also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38891765
FireEyeGeneric.mg.848652d1fc3c06e0
McAfeeGenericRXAA-AA!848652D1FC3C
CylanceUnsafe
SangforBackdoor.Win32.Saklof.gen
K7AntiVirusTrojan ( 005246d51 )
AlibabaBackdoor:Win32/Saklof.fb80efe1
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.1fc3c0
BitDefenderThetaGen:NN.ZexaF.34182.5qW@aCOvzjmb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.OLX
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Saklof.gen
BitDefenderTrojan.GenericKD.38891765
APEXMalicious
TencentWin32.Backdoor.Saklof.Eadi
EmsisoftTrojan.GenericKD.38891765 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
SophosMal/Generic-S
IkarusTrojan.Win32.FlyAgent
JiangminTrojan.BitCoinMiner.hi
AviraBDS/Redcap.cduce
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.FlyStudio.a
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojan:Win32/Tiggre!rfn
ViRobotTrojan.Win32.Z.Agent.946176.KO
ZoneAlarmHEUR:Backdoor.Win32.Saklof.gen
GDataWin32.Trojan.Flyagent.A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R273919
VBA32BScope.Trojan.Dynamer
ALYacTrojan.GenericKD.38891765
MalwarebytesTrojan.MalPack.FlyStudio
AvastWin32:TrojanX-gen [Trj]
RisingSpyware.KeyLogger!1.65B5 (CLOUD)
YandexTrojan.GenAsa!DTDJ/jK7DWk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Backdoor.Win32.Saklof?

Backdoor.Win32.Saklof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment