Backdoor

Backdoor:Win32/Rbot.OQ removal tips

Malware Removal

The Backdoor:Win32/Rbot.OQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rbot.OQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detected Armadillo packer using a known mutex
  • Detected Armadillo packer using a known registry key
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine Backdoor:Win32/Rbot.OQ?


File Info:

name: EAD0213E2DE25E395043.mlw
path: /opt/CAPEv2/storage/binaries/0d7b97636c5fc7ba4c136012f838030c1268b2f6a8716fb91722ffe099b4ea97
crc32: A772D17B
md5: ead0213e2de25e3950438a9b67b078a1
sha1: 32bac1b3092fa96dc28317b1383413c63653b9b9
sha256: 0d7b97636c5fc7ba4c136012f838030c1268b2f6a8716fb91722ffe099b4ea97
sha512: 87c721e14e003c4572c8eae496359ffbaa1beedb9e839bf6efa40e624067de72e503527b45d341b57af1b90397821c0e5ebe4df6998504b9e19b3c851bec3129
ssdeep: 98304:pR4oChHLmmmbQWjH1nJLj7XixBosm5hiIxTXIRXNY1EbWmcL5Ebj:pulhHLmmmkWpnJLj7E4iIxTXOdPWFL5k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5262344420982F7C8A1CFB2A783B3F514DFB1A4CAEC487AE9F6E7DECA4D5A4450151B
sha3_384: 49805e7e64dade2743b48b3ac42f1759f574029fd63221c6f97b3cc84086cb7e9a1ff7c86d8f8dc089e23695ff9bfc9a
ep_bytes: 60e8000000005d50510fcaf7d29cf7d2
timestamp: 2021-11-25 08:28:36

Version Info:

0: [No Data]

Backdoor:Win32/Rbot.OQ also known as:

CylanceUnsafe
Paloaltogeneric.ml
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftBackdoor:Win32/Rbot.OQ
AhnLab-V3Malware/Win32.Generic.C3569005
McAfeeArtemis!EAD0213E2DE2
MalwarebytesMalware.Heuristic.1003
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor:Win32/Rbot.OQ?

Backdoor:Win32/Rbot.OQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment