Backdoor

Backdoor:Win32/Turla.W!dha removal instruction

Malware Removal

The Backdoor:Win32/Turla.W!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Turla.W!dha virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Turla.W!dha?


File Info:

name: 2A7670AA9D1CC64E61FD.mlw
path: /opt/CAPEv2/storage/binaries/208f0339fb6cd0c2a10bda7e42deb9938ab279f56db28a017d27269dfc0802a8
crc32: 6648E862
md5: 2a7670aa9d1cc64e61fd50f9f64296f9
sha1: 490540e5d6c0c3930fee28f418e87e8e5c332bf1
sha256: 208f0339fb6cd0c2a10bda7e42deb9938ab279f56db28a017d27269dfc0802a8
sha512: 25792ca76eb7bfd0080ac9ca644d5e50722e8e3f826b907d3ec3a0d5e55bd05fc8dd66cc240567a835338edb2f4e2163673d683f2fe40018676d07aa67f0b0d1
ssdeep: 12288:/XhMqGLyZ8cA0U5js3J7LvEUHBAL7zUZ2DuHdakZHmZRK+HWS5z3:/XaLDcAHu5heBDEdAh5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15105D00AF2E5D624C955993DF0111F339AB90D73848F6A93EFAE1A286D7C1883C1EF45
sha3_384: 46ec78cb0b41f633c3739b4d15805ce5b5f715afd0d26cb9bf7926f71995f5bd618447cc432849234f27dc9b19a29376
ep_bytes: e84b6f0000e978feffff558bec83ec08
timestamp: 2013-04-01 06:37:55

Version Info:

CompanyName: Microsoft Corporation
FileDescription: System Management Installer
FileVersion: 5.1.2600.5512
InternalName: smbinst
LegalCopyright: Copyright (C) Microsoft Corp. 1997-2002.
OriginalFilename: smbinst
ProductName: Microsoft (R) Windows (R) Operating System
ProductVersion: 5.1.2600.5512
Translation: 0x0409 0x04b0

Backdoor:Win32/Turla.W!dha also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Turla.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.61
FireEyeGeneric.mg.2a7670aa9d1cc64e
McAfeeBackDoor-FCTQ!2A7670AA9D1C
CylanceUnsafe
ZillyaBackdoor.Turla.Win32.30
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b674f1 )
BitDefenderGen:Variant.Ransom.61
K7GWTrojan ( 004b674f1 )
Cybereasonmalicious.a9d1cc
ArcabitTrojan.Ransom.61
VirITBackdoor.Win32.Generic.BQAW
SymantecTrojan.Gen
ESET-NOD32Win32/Turla.AY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.12685250-1
KasperskyBackdoor.Win32.Turla.ce
AlibabaBackdoor:Win32/Turla.cfa0bbd2
NANO-AntivirusTrojan.Win32.Turla.dmyict
CynetMalicious (score: 100)
ViRobotBackdoor.Win32.S.Turla.823296
RisingMalware.Obscure!1.A3BB (CLASSIC)
Ad-AwareGen:Variant.Ransom.61
ComodoMalware@#qscepgbn8z5b
VIPREGen:Variant.Ransom.61
TrendMicroBKDR_TURLA.YLI
McAfee-GW-EditionBehavesLike.Win32.Virut.cc
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Ransom.61 (B)
IkarusTrojan.Win32.Turla
JiangminBackdoor/Turla.o
AviraTR/Turla.micie
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3D4E
KingsoftWin32.Hack.Turla.ce.(kcloud)
MicrosoftBackdoor:Win32/Turla.W!dha
GDataGen:Variant.Ransom.61
GoogleDetected
AhnLab-V3Trojan/Win32.Turla.C516364
VBA32BScope.Backdoor.Turla
ALYacBackdoor.Turla.A
TACHYONBackdoor/W32.Turla.823296
MalwarebytesMalware.AI.687463561
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_TURLA.YLI
TencentMalware.Win32.Gencirc.1201b1ab
YandexTrojan.Turla!CbxOznRvzMU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.8753593.susgen
FortinetW32/Turla.AF!tr
AVGWin32:APTX-gen [Trj]
AvastWin32:APTX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Turla.W!dha?

Backdoor:Win32/Turla.W!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment