Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

UDS:Backdoor.Win32.Blacknix removal

Published Apr 20, 2024 Backdoor category 2 min read
Report context

What to verify before removal

UDS:Backdoor.Win32.Blacknix removal deserves a credential-safety review because this backdoor label can overlap with remote access, browser data theft, or persistence after reboot. Cleanup should include scanning the file, removing the persistence point, and rotating exposed passwords from a clean device.

Start by comparing the local file name with 9E1ABE5E2B12170312E0.mlw, then review the behavior notes for credential theft, browser data access, remote-control activity, and persistence after reboot. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
9E1ABE5E2B12170312E0.mlw
  • Compare the suspicious file name with 9E1ABE5E2B12170312E0.mlw.
  • Confirm the detection name matches UDS:Backdoor.Win32.Blacknix removal before removing related files.
  • Review the report for credential theft, browser data access, remote-control activity, and persistence after reboot so the cleanup is based on observed behavior, not only the label.
  • After cleanup, rotate passwords from a clean device and review browser sessions or saved credentials.

The UDS:Backdoor.Win32.Blacknix is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What UDS:Backdoor.Win32.Blacknix virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine UDS:Backdoor.Win32.Blacknix?


File Info:

name: 9E1ABE5E2B12170312E0.mlw
path: /opt/CAPEv2/storage/binaries/103798641592be08e9e12cfc5ca06ae5bab3c8dae43210dc0d615a86d41cdedf
crc32: E13C82AF
md5: 9e1abe5e2b12170312e05a0b2cf69fca
sha1: fe01540895bcc2479a639e229754b4c21aa78dd2
sha256: 103798641592be08e9e12cfc5ca06ae5bab3c8dae43210dc0d615a86d41cdedf
sha512: 0ff73fae85ddc912ae359e4ced0095f59be7d0c5e61f5d1f52106653748ead958d225503c4b7143ffbe64663e51c6ab8905e14a47702b003de0e6291850af26a
ssdeep: 49152:6UeOMAZE9zoYrkrkndJWDBdrnn1ugrA3wXgnqNDf0:6G5ZE9MYlndJWDr11SyDf0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E85232039E1C536D5D39532CFCC6AE270E5E6098F3144B723D90A1E5E3E9DAC139B6A
sha3_384: 565383d45710406944218f3aa679facd4721133744065258137ad87ec0eb074e1e481552bc5bd2ead1ec5b5127d3094c
ep_bytes: 558bec6aff68201e4200685cd2410064
timestamp: 2010-11-18 16:27:33

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 9.20
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

UDS:Backdoor.Win32.Blacknix also known as:

Skyhigh BehavesLike.Win32.BadFile.tc
ALYac Backdoor.Agent.BlackNix
Sangfor Backdoor.Win32.Blacknix.Vmmn
Symantec Trojan.Gen.MBT
TrendMicro-HouseCall TROJ_GEN.R002H07FR23
Kaspersky UDS:Backdoor.Win32.Blacknix.gen
Google Detected
Sophos Generic Reputation PUA (PUA)
Varist W32/Delf.gen!Eldorado
ZoneAlarm HEUR:Backdoor.Win32.Blacknix.gen
Microsoft PUA:Win32/Presenoker
McAfee Artemis!9E1ABE5E2B12
VBA32 Backdoor.Blacknix
Cylance unsafe
Rising Backdoor.Blacknix!8.115BE (CLOUD)
Fortinet W32/Blacknix!tr.bdr
DeepInstinct MALICIOUS

How to remove UDS:Backdoor.Win32.Blacknix?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.