Backdoor

Backdoor:Win32/Rbot!pz removal instruction

Malware Removal

The Backdoor:Win32/Rbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rbot!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Rbot!pz?


File Info:

name: E0B5E7FFE91E68719971.mlw
path: /opt/CAPEv2/storage/binaries/ce4748a74385f19d8821bbc6612011bf31bc36e44f07d6328a87281eac45f8d6
crc32: 188A240D
md5: e0b5e7ffe91e6871997128f218de8c00
sha1: 119a1f84af25887fd01f82f79a8b336fb5408944
sha256: ce4748a74385f19d8821bbc6612011bf31bc36e44f07d6328a87281eac45f8d6
sha512: 6157e2c5357d53c0fdd83039a8909a13be30cc0356ddb59fc6feac52c97e4d55b9f2ec542158c4a6f34a3eec51c6593303ebae925e84375f51f025671abf2b3d
ssdeep: 1536:Y0ngQHkxRtN12SGjkD1yRDyPBG7XigkGYSZ97Uw4oVs+A01/n0gx38dbFRypRdnh:XvATN12Sf1NE7/LDVs+A0//N8lYVr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183830279AAB73813F1CA777AF03E604D605B7826F05120273498AC0DA18FA9FE417B5C
sha3_384: 1e21911fdb4a0e4f7a2273daec58d50a06beedbf1afe847e35dcfb6c3b3152f8c21ebf752de76b7f46f8c680e22c6917
ep_bytes: 60be00904b008dbe0080f4ff5783cdff
timestamp: 2006-09-21 13:53:27

Version Info:

0: [No Data]

Backdoor:Win32/Rbot!pz also known as:

BkavW32.Common.3442FDB0
LionicTrojan.Win32.Agent.l4i1
Elasticmalicious (moderate confidence)
MicroWorld-eScanGenPack:Generic.Sdbot.82EEB888
FireEyeGeneric.mg.e0b5e7ffe91e6871
SkyhighBehavesLike.Win32.Generic.mc
ALYacGenPack:Generic.Sdbot.82EEB888
Cylanceunsafe
SangforSuspicious.Win32.Save.a
AlibabaBackdoor:Win32/Wmfap.e9a6c153
SymantecW32.Spybot.Worm
ESET-NOD32a variant of Win32/Rbot
APEXMalicious
TrendMicro-HouseCallDIALER_WIN32DIAL
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Rbot.gen
BitDefenderGenPack:Generic.Sdbot.82EEB888
NANO-AntivirusTrojan.Win32.Rbot.prkr
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebWin32.HLLW.MyBot.based
VIPREGenPack:Generic.Sdbot.82EEB888
TrendMicroDIALER_WIN32DIAL
Trapminemalicious.high.ml.score
EmsisoftGenPack:Generic.Sdbot.82EEB888 (B)
SentinelOneStatic AI – Malicious PE
GDataGenPack:Generic.Sdbot.82EEB888
JiangminBackdoor/RBot.Gez
GoogleDetected
AviraTR/Crypt.ULPM.Gen
VaristW32/Rbot.P.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.Rbot
KingsoftWin32.Hack.Rbot.gen
XcitiumMalware@#bizpthvounxl
ArcabitGenPack:Generic.Sdbot.82EEB888
ZoneAlarmBackdoor.Win32.Rbot.gen
MicrosoftBackdoor:Win32/Rbot!pz
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!E0B5E7FFE91E
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32OScope.Backdoor.Sdbot.Cgen
MalwarebytesGeneric.Malware/Suspicious
TencentMalware.Win32.Gencirc.10bf630b
YandexTrojan.GenAsa!oRG3TZ+y3bA
IkarusBackdoor.Win32.Rbot
FortinetW32/Rbot.gen!tr
BitDefenderThetaAI:Packer.48F9A26C1E
PandaW32/Gaobot.OEW.worm
alibabacloudBackdoor:Win/AutoRun.GD

How to remove Backdoor:Win32/Rbot!pz?

Backdoor:Win32/Rbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment