Backdoor

Should I remove “SubSeven.Backdoor.Bot.DDS”?

Malware Removal

The SubSeven.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SubSeven.Backdoor.Bot.DDS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine SubSeven.Backdoor.Bot.DDS?


File Info:

name: D672E3DA4062FA24DA92.mlw
path: /opt/CAPEv2/storage/binaries/5c25b079ed16fc9c1b84381e50ec2a66cd516ccfaf9f272e8575559ce47dd0e5
crc32: F0CD9C1B
md5: d672e3da4062fa24da925e135d4eacd9
sha1: 83f1fe89275fce85dbcc8f32e239ec4551df09d2
sha256: 5c25b079ed16fc9c1b84381e50ec2a66cd516ccfaf9f272e8575559ce47dd0e5
sha512: 0f9116582731330b297e9b891cf585b2d01c3a0c5475813e3a2296b408a7790d0d6e6ea1a7954c741a57b4bee861e8741df305256425861f23ec2a41f3170bee
ssdeep: 3072:ugUQra8ADkWZnOORAmHC+wp/3vACiHBlHK:PALxRAmHC+wpPvARhlHK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1343429BEF981D437C0661ABCCD07C1D5682A76202E3D154B76E51F1C9E7E2826B7C2CA
sha3_384: f5b263f83ba03c4eec6594f0d4eec849d790ac81a5c7961905dc4aabb992c9eaef912f216429470ebfd33d0f1e6df2c3
ep_bytes: 506a00e8f8feffffbaa0004200528905
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

SubSeven.Backdoor.Bot.DDS also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Fesber.lD21
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Fugrafa.269702
ClamAVWin.Trojan.Delf-1577
FireEyeGeneric.mg.d672e3da4062fa24
Cylanceunsafe
ZillyaTrojan.SubSeven.Win32.4
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/SubSeven.b24760eb
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
CyrenW32/Backdoor.GLHZ-5384
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/SubSeven.AA
TrendMicro-HouseCallTROJ_GEN.R002C0OHA23
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.SubSeven.22
BitDefenderGen:Variant.Fugrafa.269702
NANO-AntivirusTrojan.Win32.SubSeven.dqcy
AvastWin32:SubSeven-CE [Trj]
TencentMalware.Win32.Gencirc.10bdb4d9
SophosMal/Behav-053
F-SecureBackdoor.BDS/Sub7-22.C
DrWebBackDoor.SubSeven.43
VIPREGen:Variant.Fugrafa.269702
TrendMicroTROJ_GEN.R002C0OHA23
McAfee-GW-EditionBehavesLike.Win32.Dropper.dt
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Fugrafa.269702 (B)
IkarusBackdoor.Win32.SubSeven
GDataGen:Variant.Fugrafa.269702
AviraBDS/Sub7-22.C
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.SubSeven
XcitiumBackdoor.Win32.SubSeven.b@fln51
ArcabitTrojan.Fugrafa.D41D86
ViRobotTrojan.Win.Z.Subseven.245760
ZoneAlarmBackdoor.Win32.SubSeven.22
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Xema.R157455
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.36350.pmW@a8@wAwo
VBA32Backdoor.SubSeven
MalwarebytesSubSeven.Backdoor.Bot.DDS
PandaTrj/CI.A
APEXMalicious
RisingMalware.Undefined!8.C (TFE:5:NNUzb689SbE)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.RF
AVGWin32:SubSeven-CE [Trj]
Cybereasonmalicious.9275fc
DeepInstinctMALICIOUS

How to remove SubSeven.Backdoor.Bot.DDS?

SubSeven.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment