Backdoor

Backdoor:Win32/Cycbot!pz information

Malware Removal

The Backdoor:Win32/Cycbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Cycbot!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Cycbot!pz?


File Info:

name: 1C4B31D105D2EE356881.mlw
path: /opt/CAPEv2/storage/binaries/81e4628afcdef4156969b2f9bb28e8e960c3a7eb6c6807b85f5f414677beb46c
crc32: E9BDF74E
md5: 1c4b31d105d2ee3568815e928f7eda99
sha1: 202ef54ba72f1896cebd809adbfccfc0e1b8c01b
sha256: 81e4628afcdef4156969b2f9bb28e8e960c3a7eb6c6807b85f5f414677beb46c
sha512: 6fc782fee1bfdf24c4f5c8821f6907dec37be79932326d462b8930c8a731a0cb8c676d9f9fe88e01297385f0fe33e73ae3a81c48ab932b1d8dbe52601451a296
ssdeep: 3072:7Zl7e7ve/RNnEbaTT6Sn1ccJWyyShXDfBXoKGw9G1NEQXsBOTFgM9hgyoHfTDB:Vte7W/s6mj+XvuNHs8TF9hgZbD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12904026695734A5DE3B646342CC9E628433960D3B6E50A192FC097FFB020BD5FA371D8
sha3_384: 69a7ed405fb6577f866271b9a30d50cb5b882a7581ff50f8254848b4019b9f823b2d1bcc7e59075254fd3bce30e72ea2
ep_bytes: 8bff558bec81ec640400008d85c0fcff
timestamp: 2005-09-25 07:42:52

Version Info:

0: [No Data]

Backdoor:Win32/Cycbot!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lrOY
MicroWorld-eScanGen:Variant.Ransom.Cerber.577
ClamAVWin.Trojan.Gbot-2033
FireEyeGeneric.mg.1c4b31d105d2ee35
SkyhighBehavesLike.Win32.Picsys.cc
ALYacGen:Variant.Ransom.Cerber.577
Cylanceunsafe
VIPREGen:Variant.Ransom.Cerber.577
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 003210941 )
AlibabaTrojan:Win32/Pakes.07bf93cd
K7GWBackdoor ( 003210941 )
Cybereasonmalicious.ba72f1
VirITTrojan.Win32.Cryptor.B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.VJK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Pakes.qvc
BitDefenderGen:Variant.Ransom.Cerber.577
NANO-AntivirusTrojan.Win32.Cycbot.iffez
AvastWin32:Cybota [Trj]
RisingBackdoor.Cycbot!8.850 (TFE:2:YE0X9kdau3N)
TACHYONTrojan/W32.Packer.173568.G
EmsisoftGen:Variant.Ransom.Cerber.577 (B)
F-SecureBackdoor.BDS/Cycbot.bizc
DrWebBackDoor.Gbot.1591
ZillyaTrojan.Jorik.Win32.40426
TrendMicroBKDR_CYCBOT.SMTE
Trapminemalicious.high.ml.score
SophosMal/FakeAV-IS
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.vvc
WebrootW32.Cycbot.Gen
GoogleDetected
AviraBDS/Cycbot.bizc
Antiy-AVLTrojan/Win32.Pakes
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Cycbot!pz
XcitiumBackdoor.Win32.Gbot.QAT@4k3skb
ArcabitTrojan.Ransom.Cerber.577
ZoneAlarmTrojan.Win32.Pakes.qvc
GDataWin32.Trojan.Repno.A@gen
VaristW32/Goolbot.P.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R15263
McAfeeBackDoor-EXI.gen.ab
MAXmalware (ai score=100)
VBA32Trojan.Gbot
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Cycbot.gen
TrendMicro-HouseCallBKDR_CYCBOT.SMTE
TencentMalware.Win32.Gencirc.114a4b43
YandexTrojan.Kryptik!PULZ1w1JBKE
IkarusBackdoor.Win32.Cycbot
FortinetW32/Cycbot.AF!tr
BitDefenderThetaGen:NN.ZexaF.36608.kqW@aKuaygei
AVGWin32:Cybota [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Cycbot!pz?

Backdoor:Win32/Cycbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment