Malware

About “Generic.Sdbot.A2B6C043” infection

Malware Removal

The Generic.Sdbot.A2B6C043 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Sdbot.A2B6C043 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Starts servers listening on 0.0.0.0:2006
  • Reads data out of its own binary image
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • The sample wrote data to the system hosts file.
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Generic.Sdbot.A2B6C043?


File Info:

crc32: 0BBC61E0
md5: d5b445146660b797a10ca310a37f8e7b
name: D5B445146660B797A10CA310A37F8E7B.mlw
sha1: d3bf610c07341c6dba0fd5c5ed0b01e9bd775217
sha256: bbf722de705df13f71f8fc285568fd650678ac73695ee2b8ae1755d709d3ee85
sha512: 2f879aefc1772501442e9ff0497d79631248907197ecc36832d59176e161d12ce716d0bfe9d4b624715e180c8e7eba83db04aee5baeea2bc5b57209d49672c15
ssdeep: 768:FCQgmy+EfiEZb64tlP5AEuLkQkbH6TX0sbs:FCQgmy+E6Au4hMZcaIsg
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Sdbot.A2B6C043 also known as:

LionicWorm.Win32.Jalabed.t!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Nancy
ALYacGeneric.Sdbot.A2B6C043
CylanceUnsafe
AlibabaWorm:Win32/Jalabed.ade8e9c5
Cybereasonmalicious.46660b
CyrenW32/Worm.PJXO-2630
SymantecW32.Jalabed@mm
ESET-NOD32Win32/Jalabed.A
AvastWin32:Jalabed [Wrm]
CynetMalicious (score: 100)
KasperskyEmail-Worm.Win32.Jalabed.a
BitDefenderGeneric.Sdbot.A2B6C043
NANO-AntivirusTrojan.Win32.Jalabed.glpv
MicroWorld-eScanGeneric.Sdbot.A2B6C043
Ad-AwareGeneric.Sdbot.A2B6C043
SophosTroj/Bckdr-GET
ComodoWorm.Win32.Jalabed.A@3cl9
BitDefenderThetaGen:NN.ZexaE.34142.dyY@aCK6Q5ii
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_JALABED.C
McAfee-GW-EditionBehavesLike.Win32.Mytob.pm
FireEyeGeneric.mg.d5b445146660b797
EmsisoftGeneric.Sdbot.A2B6C043 (B)
SentinelOneStatic AI – Malicious PE
JiangminI-Worm/Jalabed.a
WebrootW32.Trojan.Worm.Gen.X
AviraVBS/Zapchast
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGeneric.Sdbot.A2B6C043
McAfeeBackDoor-CXR
MAXmalware (ai score=99)
VBA32Worm.Jalabed
PandaW32/Jalabed.A.worm
TrendMicro-HouseCallWORM_JALABED.C
RisingWorm.Mail.Jalabed.a (CLASSIC)
YandexVBS.LoveLetter
MaxSecureTrojan.Malware.1672577.susgen
FortinetW32/Jalabed.A@mm
AVGWin32:Jalabed [Wrm]
Paloaltogeneric.ml

How to remove Generic.Sdbot.A2B6C043?

Generic.Sdbot.A2B6C043 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment