Malware

Generic.Sdbot.A9954CB6 malicious file

Malware Removal

The Generic.Sdbot.A9954CB6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Sdbot.A9954CB6 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Generic.Sdbot.A9954CB6?


File Info:

name: 22940008A8F8825C430B.mlw
path: /opt/CAPEv2/storage/binaries/1c319fc2429dc8047d758f92841ac39ed65cd27dc7f98d461e20dd113046a93a
crc32: 596F6098
md5: 22940008a8f8825c430bb6f538747cea
sha1: fe8f1a72d3a9109d26abf59eb9c7c026f032ebf8
sha256: 1c319fc2429dc8047d758f92841ac39ed65cd27dc7f98d461e20dd113046a93a
sha512: a2f5a13421b6265d4e722b1f872bc1d10cf71798ce9e6043bc6ea1f15334a581a42bc2dbc76d5c23d437b6d5cd464c3f5da08ce3156df553b55c00dfd4eabb7a
ssdeep: 3072:xU71iqcgYlkyWyPS7RwTLilI2nniqq04Djf9oMFcr1DaQKhN+rD:xE1iVgknWyOhljnniMQh3Fcr1Gr0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3D3028BDF15B2ABC7F31D7B519CA07117B9311A08613C0C6FE45CD3ADFB9990A8A285
sha3_384: 86d68a55f6315b6dc0f62e7b5dbee5a77164333b6daf4f253bd25e0385b4d2b91ba20143d2ed9b09d595ed50fe011778
ep_bytes: 60be002048008dbe00f0f7ff5783cdff
timestamp: 2006-02-14 15:42:30

Version Info:

0: [No Data]

Generic.Sdbot.A9954CB6 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Rbot.lgnx
Elasticmalicious (moderate confidence)
DrWebWin32.HLLW.MyBot
MicroWorld-eScanGeneric.Sdbot.A9954CB6
FireEyeGeneric.mg.22940008a8f8825c
SkyhighBehavesLike.Win32.Generic.cc
McAfeeArtemis!22940008A8F8
MalwarebytesGeneric.Malware/Suspicious
ZillyaBackdoor.RBot.Win32.17284
AlibabaBackdoor:Win32/OScope.f2241de3
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.4F32B4781E
VirITBackdoor.Win32.SdBot2.BUK
SymantecW32.SillyIM
ESET-NOD32Win32/Rbot
APEXMalicious
AvastWin32:Rbot-BFS [Trj]
ClamAVWin.Trojan.Mybot-4677
KasperskyBackdoor.Win32.Rbot.gen
BitDefenderGeneric.Sdbot.A9954CB6
NANO-AntivirusTrojan.Win32.Rbot.uugdm
TencentWin32.Backdoor.Rbot.Xmhl
EmsisoftGeneric.Sdbot.A9954CB6 (B)
F-SecureWorm.WORM/RBot.124928
VIPREGeneric.Sdbot.A9954CB6
TrendMicroWORM_SPYBOT.GEN
Trapminemalicious.high.ml.score
CMCGeneric.Win32.22940008a8!CMCRadar
SophosW32/Rbot-Gen
IkarusBackdoor.Win32.Rbot
MAXmalware (ai score=100)
JiangminBackdoor/SdBot.cum
GoogleDetected
AviraWORM/RBot.124928
VaristW32/Spybot.ZYIU-4594
Antiy-AVLTrojan[Backdoor]/Win32.Rbot
KingsoftWin32.Hack.Rbot.gen
MicrosoftBackdoor:Win32/Rbot
XcitiumBackdoor.Win32.Rbot@2hdd
ArcabitGeneric.Sdbot.A9954CB6
ViRobotBackdoor.Win32.RBot.130048.F
ZoneAlarmBackdoor.Win32.Rbot.gen
GDataGeneric.Sdbot.A9954CB6
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.C21461
VBA32OScope.Backdoor.Sdbot.Cgen
ALYacGeneric.Sdbot.A9954CB6
Cylanceunsafe
PandaW32/Gaobot.MUN.worm
TrendMicro-HouseCallWORM_SPYBOT.GEN
RisingWorm.SpyBot.ym (CLASSIC)
YandexWorm.RBot.EAB
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rbot.gen!tr
AVGWin32:Rbot-BFS [Trj]
Cybereasonmalicious.8a8f88
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Rbot.gen

How to remove Generic.Sdbot.A9954CB6?

Generic.Sdbot.A9954CB6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment