Backdoor

Dropped:Backdoor.Kollah.E (B) removal guide

Malware Removal

The Dropped:Backdoor.Kollah.E (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Backdoor.Kollah.E (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates Zeus (Banking Trojan) mutexes

How to determine Dropped:Backdoor.Kollah.E (B)?


File Info:

name: 2E366CD07824A5F9C45C.mlw
path: /opt/CAPEv2/storage/binaries/9e9dc903dd6afc0b78fdda06ae29c2dd4ed3cb6dc8c311a4b152b19d34379546
crc32: 6ACDC4EB
md5: 2e366cd07824a5f9c45ce7fdf442df67
sha1: 3d762a586465364f16226d178fa9cfd20c0abee2
sha256: 9e9dc903dd6afc0b78fdda06ae29c2dd4ed3cb6dc8c311a4b152b19d34379546
sha512: 2d4afe7f1368d781068ec0857c897a733c7e1f32320165c7b6e2648071b02c2609bd0f053e38472696bba85012679b220aa1b2c4f2d119a0af54e11e591f6e03
ssdeep: 3072:eB8GgP56KcowqyC+Y5AQrl1YTogQk+4e5Eg8kE4F8XElpXx/zXq3/1+DzYbzq:eB6yceQrl1AH7FN4Fjh/bqPWz4q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111240130728186B2D47E4076DC4B43930FB5AA66662BC6EE8E94C54B5F12FD1EF27306
sha3_384: 7edcacd49e2aa28bee36775c0d3edad6af6a410b181de947ebc6ce0c38360fe28af31e28297203360139d4a3bfb3c074
ep_bytes: 558bec81ec340400005356576a01e832
timestamp: 2009-06-25 21:14:51

Version Info:

0: [No Data]

Dropped:Backdoor.Kollah.E (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.264
MicroWorld-eScanDropped:Backdoor.Kollah.E
McAfeeGenericRXLW-CB!2E366CD07824
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 000108081 )
K7GWSpyware ( 000108081 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.07E996061F
VirITBackdoor.Win32.Agent.MPX
CyrenW32/Zbot.BS.gen!Eldorado
ESET-NOD32a variant of Win32/Spy.Agent.PZ
TrendMicro-HouseCallTROJ_ZBOT.SMUC
KasperskyTrojan-Proxy.Win32.Agent.ox
BitDefenderDropped:Backdoor.Kollah.E
NANO-AntivirusTrojan.Win32.Panda.vpjct
AvastWin32:Agent-LQE [Trj]
TencentBackdoor.Win32.Small.ha
Ad-AwareDropped:Backdoor.Kollah.E
SophosML/PE-A
ComodoTrojWare.Win32.TrojanSpy.Zbot.Gen@176vha
TrendMicroTROJ_ZBOT.SMUC
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.2e366cd07824a5f9
EmsisoftDropped:Backdoor.Kollah.E (B)
IkarusPacked.Win32.Katusha
GDataDropped:Backdoor.Kollah.E
JiangminTrojanSpy.Zbot.qkc
WebrootW32.Infostealer.Zeus
AviraTR/Rootkit.Gen
MAXmalware (ai score=83)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Zbot.DM!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hupe.Gen
Acronissuspicious
VBA32Trojan.Inject.01376
ALYacDropped:Backdoor.Kollah.E
MalwarebytesTrojan.ProxyAgent
APEXMalicious
RisingTrojan.Generic@AI.94 (RDML:tWD8fYX2F/MnmUNSxqLfVg)
YandexTrojan.GenAsa!0a2M2SLlL48
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.PZ!tr
AVGWin32:Agent-LQE [Trj]
Cybereasonmalicious.07824a
PandaTrj/Genetic.gen

How to remove Dropped:Backdoor.Kollah.E (B)?

Dropped:Backdoor.Kollah.E (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment