Backdoor

Backdoor:WinNT/Turla.B!dha removal tips

Malware Removal

The Backdoor:WinNT/Turla.B!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:WinNT/Turla.B!dha virus can do?

  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Backdoor:WinNT/Turla.B!dha?


File Info:

name: 94737D9C6B2958E0284B.mlw
path: /opt/CAPEv2/storage/binaries/f697aa0bb10ae7141fb1ee62e854616e1d650397121041fc7d502c091c4234eb
crc32: B7C9AB2C
md5: 94737d9c6b2958e0284b48b9dff2b055
sha1: 89e481f3643cb2ab17b36098373f12390746cc5e
sha256: f697aa0bb10ae7141fb1ee62e854616e1d650397121041fc7d502c091c4234eb
sha512: 97f09b523ab005a323c825c1345d694b3a1602ccf989f2c7f70583216edfec5a88908abde8fa2734af6840b051299f0cc7284ca40a3f3bf745ff1e5b194756b9
ssdeep: 49152:Gr1V6qm+/45ABY7HTtH7tB5/1tWw1rCj2mshtAUKK7IJ:Gr1V6qm+/4iC7xH7tNrIQzZ7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2D5C002E38051BAE4B381F6C6FA5225F6BAB531032556CF53805E2A6F37BD1AE35353
sha3_384: e9eaab13f7b6cad6f77f3686cdb95fb380e90f385419cb4ddbc5811ccdae150802b57235fe6e8cc9faaab975f14ba580
ep_bytes: b8afbeadde3944240875113944240c75
timestamp: 2014-08-28 10:23:36

Version Info:

0: [No Data]

Backdoor:WinNT/Turla.B!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Turla.4!c
MicroWorld-eScanGen:Variant.Agiala.16
SkyhighGenericRXRZ-BX!94737D9C6B29
McAfeeGenericRXRZ-BX!94737D9C6B29
MalwarebytesNeshta.Virus.FileInfector.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win64/Turla.2848c28a
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DBN24
KasperskyTrojan.Win64.Turla.af
BitDefenderGen:Variant.Agiala.16
NANO-AntivirusTrojan.Win32.Turla.fbbkzn
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13b37bf9
EmsisoftGen:Variant.Agiala.16 (B)
GoogleDetected
F-SecureHeuristic.HEUR/AGEN.1301976
DrWebBackDoor.Turla.83
VIPREGen:Variant.Agiala.16
TrendMicroTROJ_GEN.R002C0DBN24
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.94737d9c6b2958e0
SophosTroj/Turla-AJ
SentinelOneStatic AI – Suspicious PE
VaristW64/Agent.NBBZ
AviraTR/Turla.D.2
MAXmalware (ai score=94)
Antiy-AVLTrojan[Backdoor]/Win32.Turla
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:WinNT/Turla.B!dha
ArcabitTrojan.Agiala.16
ZoneAlarmHEUR:Backdoor.Win64.Generic
GDataGen:Variant.Agiala.16
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Turla.C2270268
BitDefenderThetaGen:NN.ZexaF.36802.RsW@aabjmJ
ALYacGen:Variant.Agiala.16
VBA32BScope.Backdoor.WinNT.Turla
Cylanceunsafe
PandaTrj/Genetic.gen
RisingRootkit.Turla!8.2F18 (TFE:4:EYvuiu4As9S)
YandexBackdoor.Agent!pinrQkcZwvM
IkarusTrojan-Spy.Turla
MaxSecureTrojan.Malware.8369084.susgen
FortinetW64/Generic!tr.bdr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Backdoor:WinNT/Turla.B!dha?

Backdoor:WinNT/Turla.B!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment