Backdoor

Backdoor:Win32/Poebot malicious file

Malware Removal

The Backdoor:Win32/Poebot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Poebot virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

xx.enterhere.biz
xx.nadnadzz.info
xx.ka3ek.com

How to determine Backdoor:Win32/Poebot?


File Info:

crc32: 62D4DE3F
md5: d816943eeb29a00ceb54ec7b012dd4f1
name: D816943EEB29A00CEB54EC7B012DD4F1.mlw
sha1: 08b5c2049d9cd02bcc00abc6a8a95263bd43fed6
sha256: 0045410825a078e8ec3371329e22d0a1a5c7708259b4a78e1797b8af4e84f0bb
sha512: 4a309433b90d122564a5b2c93f833a8a3012554e192079b5e9a24c1fe67b905799764d57008bbb4db41c3935f5d217ab5036e71ae52e60d48768973f504689c1
ssdeep: 3072:qYSyLbuvTSuCn2dyem9HGtdFhIG8EmF4oiZo9YU8W:8Yyb6n2dzm9HGtnhxDmF4owo9Yy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Poebot also known as:

K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Sdbot.945
CynetMalicious (score: 100)
ALYacBackdoor.Linkbot-M
CylanceUnsafe
ZillyaBackdoor.Nepoe.Win32.449
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Fsysna.8416a87d
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.eeb29a
CyrenW32/Backdoor.AROE-0746
SymantecBackdoor.Trojan
ESET-NOD32Win32/Poebot.NBF
APEXMalicious
AvastWin32:Delf-NCB [Drp]
ClamAVWin.Trojan.Nepoe-2
KasperskyTrojan.Win32.Fsysna.cizw
BitDefenderGen:Variant.Graftor.Elzob.8763
NANO-AntivirusTrojan.Win32.Nepoe.bamuh
ViRobotBackdoor.Win32.Nepoe.31744
MicroWorld-eScanGen:Variant.Graftor.Elzob.8763
TencentWin32.Trojan.Fsysna.Wpsw
Ad-AwareGen:Variant.Graftor.Elzob.8763
SophosMal/Generic-R + Troj/Poebot-NJ
ComodoTrojWare.Win32.Poebot.NBF1@1lq5mc
BitDefenderThetaAI:Packer.97FC1D581E
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_LAMEWAR.VTG
McAfee-GW-EditionBehavesLike.Win32.Wabot.cc
FireEyeGeneric.mg.d816943eeb29a00c
EmsisoftGen:Variant.Graftor.Elzob.8763 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Nepoe.cn
WebrootVir.Tool.Gen
AviraDR/Delphi.Gen
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.126C
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Poebot.gen
SUPERAntiSpywareTrojan.Agent/Gen
GDataGen:Variant.Graftor.Elzob.8763
AhnLab-V3Backdoor/Win32.Nepoe.R44008
Acronissuspicious
McAfeeGeneric.dx!D816943EEB29
MAXmalware (ai score=100)
VBA32BScope.Trojan.Palevo.06
PandaBck/Poebot.NY
TrendMicro-HouseCallTROJ_LAMEWAR.VTG
RisingTrojan.Spy.Win32.Zbot.fwh (CLASSIC)
YandexBackdoor.Nepoe.HM
IkarusP2P-Worm.Win32.Palevo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.fam!tr
AVGWin32:Delf-NCB [Drp]

How to remove Backdoor:Win32/Poebot?

Backdoor:Win32/Poebot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment