Backdoor

Backdoor:Win32/Sdbot (file analysis)

Malware Removal

The Backdoor:Win32/Sdbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Sdbot virus can do?

  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
irc.blackcarder.net
ircd.oharra.biz

How to determine Backdoor:Win32/Sdbot?


File Info:

crc32: 7D8F07B5
md5: b0cc963c2d15e045f84c34df615a5cfa
name: B0CC963C2D15E045F84C34DF615A5CFA.mlw
sha1: cddd7600c77df871a403a1cb6e2798ae92d12b83
sha256: f8f093159d58603f8d0055e1f60706152a6e42780bc934d87015024a41065f7c
sha512: 7ac3a479fda144d667ce9983dfb63b09f9f61d4d2c843067705ef6db76b48c986038adfe71b2ba751f9c4272ff8458d3d61f933ba6c46addef30cd0eaec5febd
ssdeep: 1536:asyUVcqf4bnECyxNaNR7r2TYujud10R1K8LKsHvYu/8l6DebFvz6:GocECyxNaNR7rKjudKhDvYu/8l6DSve
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Sdbot also known as:

BkavW32.AIDetect.malware2
K7AntiVirusBackdoor ( 004093e91 )
LionicTrojan.Win32.Generic.l486
Elasticmalicious (high confidence)
DrWebWin32.IRC.Bot.based
CynetMalicious (score: 100)
ALYacGeneric.Sdbot.D00ACD61
CylanceUnsafe
ZillyaBackdoor.SdBot.Win32.11766
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaBackdoor:Win32/SdBot.17370343
K7GWBackdoor ( 004093e91 )
Cybereasonmalicious.c2d15e
CyrenW32/Bloop.A.gen!Eldorado
SymantecW32.Spybot.Worm
ESET-NOD32a variant of Win32/Rbot
APEXMalicious
AvastWin32:Rbot-CSN [Trj]
ClamAVWin.Trojan.Trojan-532
KasperskyBackdoor.Win32.SdBot.yx
BitDefenderGeneric.Sdbot.D00ACD61
NANO-AntivirusTrojan.Win32.SdBot.dexbjn
ViRobotBackdoor.Win32.A.IRCBot.89088.A
MicroWorld-eScanGeneric.Sdbot.D00ACD61
TencentWin32.Backdoor.Sdbot.Pezk
Ad-AwareGeneric.Sdbot.D00ACD61
SophosML/PE-A + W32/Sdbot-Fam
ComodoBackdoor.Win32.Rbot.~gen@1xtqdu
BitDefenderThetaAI:Packer.8B6C349F1E
VIPRETrojan.Win32.Ircbot!cobra (v)
TrendMicroWORM_RBOT.GEN-1
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mh
FireEyeGeneric.mg.b0cc963c2d15e045
EmsisoftGeneric.Sdbot.D00ACD61 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Agobot.Gen.f
WebrootW32.Malware.Gen
AviraBDS/SdBot.Q.Plus
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.960C91
MicrosoftBackdoor:Win32/Sdbot.gen
ArcabitGeneric.Sdbot.D00ACD61
ZoneAlarmHEUR:Worm.Win32.Generic
GDataGeneric.Sdbot.D00ACD61
TACHYONBackdoor/W32.SdBot.89088.F
AhnLab-V3Win32/IRCBot.worm.Gen
Acronissuspicious
McAfeeW32/Sdbot.b.gen.g
MAXmalware (ai score=100)
VBA32OScope.Backdoor.Sdbot.Cgen
PandaW32/Gaobot.gen.worm
TrendMicro-HouseCallWORM_RBOT.GEN-1
RisingBackdoor.Rbot!1.65A6 (CLASSIC)
YandexWorm.SdBot.Gen.26
IkarusBackdoor.Rbot
MaxSecureTrojan.Malware.41677.susgen
FortinetW32/SDBot.REO!tr.bdr
AVGWin32:Rbot-CSN [Trj]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Sdbot?

Backdoor:Win32/Sdbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment