Backdoor

Medbot.Backdoor.Bot.DDS (file analysis)

Malware Removal

The Medbot.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Medbot.Backdoor.Bot.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Medbot.Backdoor.Bot.DDS?


File Info:

name: A18CE82F980BDBC3CE18.mlw
path: /opt/CAPEv2/storage/binaries/25e818743dd370fc67db17612696525c785121457b2cf8d8d38f1d629146fc94
crc32: 974ABA0E
md5: a18ce82f980bdbc3ce183a6dd1afaee5
sha1: 7072a98448f807b76469a3a24c93bd3c4061c74c
sha256: 25e818743dd370fc67db17612696525c785121457b2cf8d8d38f1d629146fc94
sha512: 1b9e5a6282426c0bff4f6abe89b761fc0b99f4bac44232a6a600fe2db1280d4c34da877aa0ea2b1ec39835cc1791605931bdf7af29c5eeaf75d86ed6f586752a
ssdeep: 12288:iY+1L3WXc3ajG+hjQKymY8efKCpD7Gj9G6G1qT8nQkCu83L3Wl/np9DBDt3kbE:A3WsqjnhMgeiCl7G0nehbGZpbD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA552377B2C851B2D82249F182B5E60DA923FD514B3089C7AB5B2DBEE7715C08F39217
sha3_384: 789cad73e2c8116579d5ae8a061532c4c47475c2ba76ccca536f92ad32f511fb083edc1e3dd6bbc5e84b3dd7a9871c99
ep_bytes: 6a6068c8f84000e866360000bf940000
timestamp: 2013-08-02 12:54:39

Version Info:

0: [No Data]

Medbot.Backdoor.Bot.DDS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealW32.Expiro.R3
MalwarebytesMedbot.Backdoor.Bot.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0059041f1 )
K7GWVirus ( 0059041f1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanWin32.Expiro.Gen.7
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
TACHYONVirus/W32.Movia
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
FireEyeGeneric.mg.a18ce82f980bdbc3
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
VaristW32/Expiro.AU.gen!Eldorado
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.AA!MTB
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
GoogleDetected
ALYacWin32.Expiro.Gen.7
MAXmalware (ai score=88)
VBA32Trojan.Sabsik.TE
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.90 (RDML:ezYtXQyzoXFwT4OP72cJ1A)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.448f80
DeepInstinctMALICIOUS

How to remove Medbot.Backdoor.Bot.DDS?

Medbot.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment