Backdoor

What is “Backdoor:Win32/Htbot.B”?

Malware Removal

The Backdoor:Win32/Htbot.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Htbot.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Htbot.B?


File Info:

name: A64F21D7BC4F4D3D680B.mlw
path: /opt/CAPEv2/storage/binaries/f1485e53403de8c654783ce3e0adf754639542e41c2a89b92843ce8ecdeb4646
crc32: 9D40B7A3
md5: a64f21d7bc4f4d3d680b3bf4cf8f7d3f
sha1: 75233e60a52d548b27f9a4ea19b75d2a9852f073
sha256: f1485e53403de8c654783ce3e0adf754639542e41c2a89b92843ce8ecdeb4646
sha512: 71fabd805e6e2e8fa390bacb5809e1512e7f7e68ce52a758983e9d57d79b18efab6ed16d0f00ec2fd4d1f7d2428cc94c59715ffcec318b7519888250162ece59
ssdeep: 3072:CKNiJfZW1fV/QUWrZD12mYFqegKvXJ61/mVWhLgBiK7IOShegz:pQJfZW1fV/QUWlDwDFnvsWrM+U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B149E37F73088F2C127C9F45AB8E90D2825C921162796CB698C77DB0B7639B97D0762
sha3_384: 3e805d4c4f7043fb074d5badb2be00dd70191bb7f1156f3cecf54b9ff1f6f3fc276b5b79b85d70a82e520a08c6f0c1ee
ep_bytes: e8362d0000e989feffffc7019c624200
timestamp: 2015-08-13 19:30:35

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Self-Extracting Cabinet
FileVersion: 6.3.0015.0
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SFXCAB.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.3.0015.0
Translation: 0x0409 0x04b0

Backdoor:Win32/Htbot.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Foreign.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34160694
FireEyeGeneric.mg.a64f21d7bc4f4d3d
CAT-QuickHealTrojan.Generic.B4
McAfeeRDN/Generic BackDoor
Cylanceunsafe
ZillyaTrojan.Foreign.Win32.53546
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
AlibabaRansom:Win32/Foreign.133f84cd
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecBackdoor.Proxyback
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.DTOO
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Foreign.oczp
BitDefenderTrojan.Generic.34160694
NANO-AntivirusTrojan.Win32.RiskGen.dvkegd
AvastWin32:Malware-gen
TACHYONRansom/W32.Foreign.202240
EmsisoftTrojan.Generic.34160694 (B)
F-SecureHeuristic.HEUR/AGEN.1323718
DrWebBackDoor.Htbot.6
VIPRETrojan.Generic.34160694
TrendMicroBKDR_HTBOT.AD
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Generic.34160694
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1323718
Antiy-AVLTrojan[Ransom]/Win32.Foreign
Kingsoftmalware.kb.a.988
XcitiumMalware@#2c9t9az3u76xj
ArcabitTrojan.Generic.D2094036
ViRobotBackdoor.Win32.ProxyBack.202240
ZoneAlarmTrojan-Ransom.Win32.Foreign.oczp
MicrosoftBackdoor:Win32/Htbot.B
GoogleDetected
AhnLab-V3Trojan/Win32.Gen
ALYacTrojan.Generic.34160694
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Htbot
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_HTBOT.AD
RisingTrojan.Generic@AI.92 (RDML:eYsIvdCaqNrD4JnCxdo1Gw)
YandexTrojan.Foreign!ozhn78QAwCw
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EJXP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.0a52d5
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Htbot.B?

Backdoor:Win32/Htbot.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment