Backdoor

Should I remove “Backdoor.RevetRat”?

Malware Removal

The Backdoor.RevetRat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.RevetRat virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

0077.duckdns.org

How to determine Backdoor.RevetRat?


File Info:

crc32: 20E89016
md5: 857395c22c5bd4b707376b4cfc7c6308
name: upload_file
sha1: 263349185213ccf520dbcd246f02fcc2d515bd6b
sha256: c6204984759803b0498b654dc19e74e5d8791f398d98e3db290da1c89c832004
sha512: 1c63b6ab3b62bf8fc980d0f033fdf41a6fcac11334193cc100f70a79c196bf7135dc8ad0de9b94339c63a9beb65e9c8c05296ef420bd06ae2c48979f9e07f89e
ssdeep: 384:7t9+Xi9NVzGS7P9oDPlMNcLlb5sVKwyK5Ct:7t9+Xi9NkwclMNEyo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor.RevetRat also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.RevetRat.2
MicroWorld-eScanGen:Variant.Razy.478777
FireEyeGeneric.mg.857395c22c5bd4b7
CAT-QuickHealTrojan.MsilFC.S6060625
McAfeeGenericRXEK-KS!857395C22C5B
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.478777
K7GWTrojan ( 700000121 )
Cybereasonmalicious.22c5bd
InvinceaML/PE-A + Mal/Revet-A
BitDefenderThetaGen:NN.ZemsilF.34254.biW@a0uJ8@l
CyrenW32/Revetrat.A.gen!Eldorado
SymantecTrojan.Revetrat
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.RevengeRat-6344273-0
KasperskyHEUR:Trojan.Win32.RRAT.gen
RisingBackdoor.Revetrat!1.B8DA (CLASSIC)
Ad-AwareGen:Variant.Razy.478777
SophosMal/Revet-A
ComodoTrojWare.MSIL.Revetrat.A@7osjcj
F-SecureTrojan.TR/ATRAPS.Gen
ZillyaTrojan.Agent.Win32.734887
TrendMicroBKDR_REVET.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
EmsisoftGen:Variant.Razy.478777 (B)
SentinelOneDFI – Malicious PE
GDataGen:Variant.Razy.478777
AviraTR/ATRAPS.Gen
ArcabitTrojan.Razy.D74E39
ZoneAlarmHEUR:Trojan.Win32.RRAT.gen
MicrosoftBackdoor:MSIL/RevengeRat.GA!MTB
CynetMalicious (score: 100)
VBA32Backdoor.RevetRat
ALYacGen:Variant.Razy.478777
MAXmalware (ai score=88)
MalwarebytesBackdoor.RevengeRAT
ESET-NOD32a variant of MSIL/Agent.APN
TrendMicro-HouseCallBKDR_REVET.SM
IkarusBackdoor-Rat.Revenge
eGambitTrojan.Generic
FortinetMSIL/RevengeRat.APN!tr
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.3FEF.Malware.Gen

How to remove Backdoor.RevetRat?

Backdoor.RevetRat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment