Malware

Generic.Sdbot.4970096D (file analysis)

Malware Removal

The Generic.Sdbot.4970096D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Sdbot.4970096D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generic.Sdbot.4970096D?


File Info:

name: 8977D86AC3C567F1ED7A.mlw
path: /opt/CAPEv2/storage/binaries/dfafb0ed63808056ffebb8bc2e034c30a0a2aa6c69909c9e3a5ddc516aa4d085
crc32: 41DAF778
md5: 8977d86ac3c567f1ed7a9606fc4e32a8
sha1: ad00be223234828a6c690dec6e790496385df425
sha256: dfafb0ed63808056ffebb8bc2e034c30a0a2aa6c69909c9e3a5ddc516aa4d085
sha512: 87a3cc3ae5bcf739aff6641fa598a47e6e8dbcb7743c0934b4d036964790a21be05aa96ef9a0ccf15d1e9e83dac4460d51529290b8f95bea3ccdf733d56acfd0
ssdeep: 3072:hudG3NxdP1LisdRO8qc1LucOzwFEP++Q:gdGBPrR+pk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDA3120AB6B11EB2C953D93FD863094F59E489B32C70CE299F69B8D5D179C214FC0D85
sha3_384: 387898ba0114166b3de4f87d84aba93fa99dfb08ea5841528cedab43ff4ee61ea5b9537989e00791a55d62981e7c1304
ep_bytes: 60e8edffffffebb3c60dc69363c60ba2
timestamp: 2006-03-26 09:47:24

Version Info:

0: [No Data]

Generic.Sdbot.4970096D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Rbot.m!c
MicroWorld-eScanGeneric.Sdbot.4970096D
ClamAVWin.Trojan.Mybot-7461
FireEyeGeneric.mg.8977d86ac3c567f1
SkyhighBehavesLike.Win32.Generic.nc
McAfeeW32/Sdbot.worm.cq.gen.bs
Cylanceunsafe
ZillyaBackdoor.RBot.Win32.20130
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Wmfap.1359e50f
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaAI:Packer.9E1DCDC621
VirITBackdoor.RBot.QL
SymantecW32.IRCBot
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Rbot
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Rbot.akm
BitDefenderGeneric.Sdbot.4970096D
NANO-AntivirusTrojan.Win32.Rbot.puyn
AvastWin32:Rbot-BRM [Trj]
TencentWin32.Backdoor.Rbot.Kmnw
TACHYONBackdoor/W32.RBot.101376.M
SophosW32/Rbot-Gen
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebWin32.HLLW.MyBot.based
VIPREGeneric.Sdbot.4970096D
TrendMicroWORM_RBOT.ITE
Trapminemalicious.high.ml.score
EmsisoftGeneric.Sdbot.4970096D (B)
IkarusPacked.Win32.PolyCrypt
JiangminBackdoor/Agobot.byy
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.Rbot
KingsoftWin32.Hack.Rbot.akm
MicrosoftBackdoor:Win32/IRCbot.gen!Z
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitGeneric.Sdbot.D4BD670D
ViRobotBackdoor.Win32.RBot.101376.V
ZoneAlarmBackdoor.Win32.Rbot.akm
GDataGeneric.Sdbot.4970096D
VaristW32/Rbot.P.gen!Eldorado
AhnLab-V3Worm/Win32.IRCBot.C20576
VBA32SScope.Backdoor.SdBot.yx
ALYacGeneric.Sdbot.4970096D
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaMalicious Packer
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallWORM_RBOT.ITE
RisingBackdoor.Rbot!8.2D8 (TFE:4:zK6F5OAcBuP)
YandexWorm.Rbot!ZPbQArHr6p0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.50798.susgen
AVGWin32:Rbot-BRM [Trj]
DeepInstinctMALICIOUS

How to remove Generic.Sdbot.4970096D?

Generic.Sdbot.4970096D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment