Backdoor

Should I remove “Backdoor:Win32/Mdmbot.G!dha”?

Malware Removal

The Backdoor:Win32/Mdmbot.G!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Mdmbot.G!dha virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Mdmbot.G!dha?


File Info:

name: 42BD5E7E8F74C15873FF.mlw
path: /opt/CAPEv2/storage/binaries/0d52b01923a064dac1733ad8efca5e9b7fa0ee569c36672125641dc3a0f445b5
crc32: 6F6938C9
md5: 42bd5e7e8f74c15873ff0f4a9ce974cd
sha1: fca78662d2f1e0df85f3dcba561195bac1227b02
sha256: 0d52b01923a064dac1733ad8efca5e9b7fa0ee569c36672125641dc3a0f445b5
sha512: d185dd86bcdda22ea4d4ef6e902b21b60c1270bf6382526908c8fe43a5e3e68bdb1e7bd8b2f2a648d811e9be97029015f192578a877f05316a0e50a57fdbc146
ssdeep: 3072:mHLp1rAcLrCR5RtwioCbwIE+W9ONlgi1IZbkv:uNOLnmONuiyZ4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C14006B3E9B197BF05DE8B6B20A1DC716290FB9605742C16FA34BC5009F9E259FB013
sha3_384: 3f39db02178e9b39380018ae880a915a12e8582414fc632a78aea73fc44c862743cb7be3178baa9086d44aac19399394
ep_bytes: 558bec6aff68e8234000685617400064
timestamp: 2013-04-27 19:56:06

Version Info:

Comments:
CompanyName:
FileDescription: javaupdate
FileVersion: 3, 0, 0, 1
InternalName: javaupdate
LegalCopyright: Copyright (C) 2013
LegalTrademarks:
OriginalFilename: javaupdate.exe
PrivateBuild:
ProductName: javaupdate
ProductVersion: 3, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Backdoor:Win32/Mdmbot.G!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.ts4L
MicroWorld-eScanGen:Variant.Mikey.139909
ClamAVWin.Trojan.Hydraq-219
FireEyeGeneric.mg.42bd5e7e8f74c158
McAfeeGenericRXAA-FA!42BD5E7E8F74
Cylanceunsafe
ZillyaDownloader.Agent.Win32.176158
SangforBackdoor.Win32.Mdmbot.V2nl
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Mdmbot.13f622e1
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
VirITTrojan.Win32.Crypt.BXGW
CyrenW32/Trojan.BEAC-0932
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Plugax.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Agent.gzjy
BitDefenderGen:Variant.Mikey.139909
NANO-AntivirusTrojan.Win32.Agent.crdafx
SUPERAntiSpywareTrojan.Agent/Gen-Bumat
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bc363c
TACHYONTrojan-Downloader/W32.Agent.200704.DH
EmsisoftGen:Variant.Mikey.139909 (B)
F-SecureHeuristic.HEUR/AGEN.1340396
DrWebBackDoor.Poison.1033
VIPREGen:Variant.Mikey.139909
TrendMicroTROJ_KRYPTIK.QPB
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Mikey.139909
JiangminTrojanDownloader.Agent.fdhp
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1340396
Antiy-AVLTrojan[Downloader]/Win32.Agent
XcitiumMalware@#wx6bx22v6kyt
ArcabitTrojan.Mikey.D22285
ViRobotBackdoor.Win32.Agent.200704.G
ZoneAlarmTrojan-Downloader.Win32.Agent.gzjy
MicrosoftBackdoor:Win32/Mdmbot.G!dha
GoogleDetected
AhnLab-V3Backdoor/Win32.Etso.R53875
BitDefenderThetaGen:NN.ZexaF.36250.mq0@aONQZfhj
ALYacTrojan.Agent.200704
MAXmalware (ai score=100)
VBA32TrojanDownloader.Agent
MalwarebytesMalware.AI.3630157792
PandaGeneric Malware
TrendMicro-HouseCallTROJ_KRYPTIK.QPB
RisingBackdoor.Mdmbot!8.2049 (TFE:5:EcSEDsBUZN)
YandexTrojan.Plugax!dr/f2r5A7aY
IkarusTrojan.Win32.Plugax
MaxSecureTrojan.Malware.5714249.susgen
FortinetW32/Kryptik.ASPO
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Mdmbot.G!dha?

Backdoor:Win32/Mdmbot.G!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment