Backdoor

Backdoor:Win32/Ciadoor.124.A removal tips

Malware Removal

The Backdoor:Win32/Ciadoor.124.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Ciadoor.124.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Ciadoor.124.A?


File Info:

name: B17A8225F9880B2BA0D4.mlw
path: /opt/CAPEv2/storage/binaries/0907e0c4c1e30ab07c21e232ceadfc932f7ac0ff93a9f7d4323ad4a0530ebc5c
crc32: 8C40F8E6
md5: b17a8225f9880b2ba0d4f16659126a33
sha1: 410bccae5c97059127bd24a1710577a35efb5772
sha256: 0907e0c4c1e30ab07c21e232ceadfc932f7ac0ff93a9f7d4323ad4a0530ebc5c
sha512: 0ea6dbfdac8c453c6c3b663a306199f8d9fe3603c5349adb1674681fb8200b49854613d22d817aef713ea49a833d73d08fdb623cbc91db8c5f28cd55c7df0a7b
ssdeep: 12288:7bsQlVBJYfWFO/TM/YHtW5Z2Cx4KFrNjZZ/0tWttMlCndydBtwGMf0Tu6l:0KVzXeYgLK5hZZMk3YCnoLTu2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153D42207E259C071F4B29E397D92862B67317FA2B93CD01A744CEDCEDE3A0C58806756
sha3_384: a30c47a546672b049f89d4810d1e574b8685b873c062baf9ff626aa653c4be88d516932b68448b235f8e1ff30d581cfb
ep_bytes: 558bec83c4b853565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: BM-productions
FileDescription: SmartClose Setup
FileVersion: 1.0
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Backdoor:Win32/Ciadoor.124.A also known as:

BkavW32.Common.92FC8723
CynetMalicious (score: 100)
FireEyeBackdoor.Generic.904146
SkyhighArtemis!Trojan
McAfeeArtemis!B17A8225F988
Cylanceunsafe
SangforBackdoor.Win32.Ciadoor.Vxhy
AlibabaTrojan:Win32/Ciadoor.4495e308
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Ciadoor.124.A
BitDefenderBackdoor.Generic.904146
NANO-AntivirusTrojan.Win32.Cia.wazvd
MicroWorld-eScanBackdoor.Generic.904146
AvastWin32:CiaDoor-AOK [PUP]
TencentWin32.Backdoor.Ciadoor.Tzfl
SophosMal/Generic-S
F-SecureBackdoor.BDS/Ciadoor.124.A.4
DrWebBackDoor.Cia.124
VIPREBackdoor.Generic.904146
TrendMicroBKDR_ASB.B
EmsisoftBackdoor.Generic.904146 (B)
GDataBackdoor.Generic.904146
WebrootW32.Malware.Heur
VaristW32/Backdoor.GHTE-2625
AviraBDS/Ciadoor.124.A.4
Antiy-AVLTrojan/Win32.SGeneric
XcitiumMalware@#lxjfh9r6bd0y
ArcabitBackdoor.Generic.DDCBD2
MicrosoftBackdoor:Win32/Ciadoor.124.A
GoogleDetected
ALYacBackdoor.Generic.904146
VBA32Backdoor.Cia
MalwarebytesMalware.AI.1853240534
TrendMicro-HouseCallBKDR_ASB.B
RisingBackdoor.CiaDoor.124 (CLOUD)
YandexTrojan.GenAsa!0klmCocoecw
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Malware.195828244.susgen
FortinetW32/Krap.A!tr.bdr
AVGWin32:CiaDoor-AOK [PUP]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Ciadoor.124.A?

Backdoor:Win32/Ciadoor.124.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment