Backdoor

About “Backdoor.Win32.Terbix” infection

Malware Removal

The Backdoor.Win32.Terbix is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Terbix virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Backdoor.Win32.Terbix?


File Info:

name: 84E38C4E6A3B05DB499F.mlw
path: /opt/CAPEv2/storage/binaries/cded67dfa65185dd4f1f971616a348831a0b386bd7594b5494fba4b69ffc5e5c
crc32: 7E06DEC9
md5: 84e38c4e6a3b05db499f140b28637a82
sha1: 8c694d99b6e47ea3940d79491a4d8a917985a459
sha256: cded67dfa65185dd4f1f971616a348831a0b386bd7594b5494fba4b69ffc5e5c
sha512: 17137558c43eae99b5cf0a427055cdd545cbb0c9a49a1895081d93a305ce759f4e7ff68b6a33f803d22f54d55ee62c26d90c65cde72a2a640afad558076161db
ssdeep: 12288:Rwz+NQ9a8zNQ1dLW16C7+vU4gT+rRvutt8c2PI/4d6fPwpkR5wdUl9qxruC1pGMj:RwCNQk8sCIE+N2tt8c2Ps+Ol9OXA2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DF4AF51BD81C0B3E261117094BEDB765D3DBD281B2099DBE3C04F7A99202D1AF3A76E
sha3_384: 44c72b7673f05eb45af5a7b2ac8f7f9a25bc6734570eae80232d15535d23c27e69c13656f6681a7d6f3da65134e47ca0
ep_bytes: e8dd0e0000e974feffffcccccc833de4
timestamp: 2021-01-20 06:11:12

Version Info:

FileVersion: 1.0.0.3
LegalCopyright: Copyright (C) 2020
ProductVersion: 1.0.0.3
Translation: 0x1809 0x04b0

Backdoor.Win32.Terbix also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Terbix.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.84e38c4e6a3b05db
McAfeeGenericRXTF-SK!84E38C4E6A3B
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Terbix.85c8d83f
K7GWTrojan ( 00564b521 )
K7AntiVirusTrojan ( 00564b521 )
CyrenW32/Trojan.TWXC-5756
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.ABVH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Terbix.gen
BitDefenderTrojan.GenericKD.45854902
NANO-AntivirusTrojan.Win32.Terbix.ioknmc
MicroWorld-eScanTrojan.GenericKD.45854902
AvastWin32:Malware-gen
TencentWin32.Backdoor.Terbix.Eckh
Ad-AwareTrojan.GenericKD.45854902
SophosMal/Generic-S
ComodoMalware@#ne5ek0kq3bbk
DrWebTrojan.Siggen12.29369
ZillyaBackdoor.Terbix.Win32.2
TrendMicroBackdoor.Win32.TERBIX.A
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
EmsisoftTrojan.GenericKD.45854902 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.45854902
JiangminBackdoor.Terbix.b
WebrootW32.Malware.Gen
AviraBDS/Redcap.azmmx
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.Generic.D2BBB0B6
MicrosoftBackdoor:Win32/Aicat.A!ml
AhnLab-V3PUP/Win.Generic.R373917
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.45854902
MAXmalware (ai score=87)
MalwarebytesBackdoor.Agent
TrendMicro-HouseCallBackdoor.Win32.TERBIX.A
RisingTrojan.Mlxg!1.CBEA (CLASSIC)
YandexBackdoor.Redcap!PljIuQjKO+Y
IkarusRootkitAgent
MaxSecureTrojan.Malware.114383961.susgen
FortinetW32/Terbix!tr.bdr
BitDefenderThetaGen:NN.ZexaF.34742.Su0@ay29j9pi
AVGWin32:Malware-gen
Cybereasonmalicious.e6a3b0
PandaTrj/CI.A

How to remove Backdoor.Win32.Terbix?

Backdoor.Win32.Terbix removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment