Backdoor

Backdoor:Win32/Bandok removal

Malware Removal

The Backdoor:Win32/Bandok is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bandok virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid
  • CAPE detected the Bandook malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Bandok?


File Info:

name: AC767D60ED12AC4A8BB8.mlw
path: /opt/CAPEv2/storage/binaries/e1a3acf7975aac4ee9421a362c4ec0d12a6389087f572543e1ed08815dc1528a
crc32: 0645C4C9
md5: ac767d60ed12ac4a8bb8f4e3b0588a8e
sha1: 4c2f2b5781e9cfe55a406163d60ff94584f4ee43
sha256: e1a3acf7975aac4ee9421a362c4ec0d12a6389087f572543e1ed08815dc1528a
sha512: ef613d5f99f67617973915d87eb425259b7da81f1408205383f85dc10e75cac50e243295e29bf18ef8250b46132e6b6694c6b5e6a0d47b72cd058c6f18c151dc
ssdeep: 1536:rkCG4PKbODh58eRb07ncaldeEP2vTxwDwSKPP8cGaLAy+uRZhOBJrgnNWM+++POw:rklqKIseRbEB7DqGaUyN+rqWM+++POUT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4A3D64552E884ADD86AB47103169F73DDBCFAB37C79AC03EBE44A21057A6F15B1820F
sha3_384: 530cbea7eed921a513820a56591638642b944a02010559949a9a73ada4e8b555f806e1753b7b9120cf051594cc8493c6
ep_bytes: 558bec83ec60c645ec00e8b8e4ffff8d
timestamp: 2007-04-02 04:35:22

Version Info:

0: [No Data]

Backdoor:Win32/Bandok also known as:

LionicTrojan.Win32.Bandok.kYPC
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Bandok-5
CAT-QuickHealBackdoor.BandokRI.S27799953
SkyhighBehavesLike.Win32.StartPage.nh
ALYacBackdoor.Bandok.BJ
MalwarebytesBandok.Backdoor.RAT.DDS
VIPREBackdoor.Bandok.BJ
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000008ab1 )
BitDefenderBackdoor.Bandok.BJ
K7GWTrojan ( 000008ab1 )
Cybereasonmalicious.0ed12a
BaiduWin32.Backdoor.Bandok.b
VirITTrojan.Win32.Generic.CI
SymantecBackdoor.Trojan
ESET-NOD32Win32/Bandok.AV
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Bandok.be
AlibabaBackdoor:Win32/Bandok.aacf5609
NANO-AntivirusTrojan.Win32.Iam.gplp
SUPERAntiSpywareBackdoor.Bandok
MicroWorld-eScanBackdoor.Bandok.BJ
AvastWin32:Bandok-W [Trj]
RisingBackdoor.Agent.hfl (CLASSIC)
EmsisoftBackdoor.Bandok.BJ (B)
F-SecureBackdoor:W32/Koodban.gen!A
DrWebBackDoor.Iam
ZillyaBackdoor.Bandok.Win32.1082
TrendMicroBKDR_BANDOK.AU
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ac767d60ed12ac4a
SophosMal/Bandook-A
SentinelOneStatic AI – Suspicious PE
GDataBackdoor.Bandok.BJ
JiangminTrojan/Agent.or
WebrootW32.Backdoor.Bandook
GoogleDetected
AviraTR/Bandok.A
Antiy-AVLTrojan[Backdoor]/Win32.Bandok
KingsoftWin32.Hack.Bandok.be
XcitiumBackdoor.Win32.Bandok.AV@2bqu
ArcabitBackdoor.Bandok.BJ
ViRobotBackdoor.Win32.Bandok.98304.C
ZoneAlarmBackdoor.Win32.Bandok.be
MicrosoftBackdoor:Win32/Bandok
VaristW32/Backdoor.QYZO-3885
AhnLab-V3Trojan/Win32.Agent.C57062
McAfeeBackDoor-CSN.g
TACHYONBackdoor/W32.Bandok.98304
VBA32BScope.Trojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_BANDOK.AU
TencentMalware.Win32.Gencirc.10b14adc
IkarusBackdoor.Win32.Bandok
FortinetW32/Bandok.NAK!tr
BitDefenderThetaAI:Packer.D5A76C351E
AVGWin32:Bandok-W [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudBackdoor:Win/Bandok.AV

How to remove Backdoor:Win32/Bandok?

Backdoor:Win32/Bandok removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment