Backdoor

Should I remove “Backdoor.TVRat.Dropper”?

Malware Removal

The Backdoor.TVRat.Dropper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TVRat.Dropper virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.TVRat.Dropper?


File Info:

name: 70EE75C5BEE044D1AE3E.mlw
path: /opt/CAPEv2/storage/binaries/eed48bf8093cf1a89a075b6be69512110a0ea650ccd111fba034aefddf4eb8ea
crc32: 0DCA7D30
md5: 70ee75c5bee044d1ae3e74212098ed29
sha1: 3a32f2e6c9d85c211ba573c039c25673d8ccae44
sha256: eed48bf8093cf1a89a075b6be69512110a0ea650ccd111fba034aefddf4eb8ea
sha512: 83dc5a12d9f4d3661eff6d557b242d392edf5d1b59ab6be0cf371208f84803f127963350077d0963548d68b465c3b209c1c318190d50b44781f991bd906a34e5
ssdeep: 98304:3BkMA37sgHUz3NDG9uEytlI/L+7Te0z1Tcfu+2B/UwDaNeSr1lE:xgrsgHUACI/K7Te0z15b/UwDleu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C136330622B10570E91E91350C43D84D26B2F5DD19F4DBA879ECAD4AAF7E3ECEA1D302
sha3_384: 00539242ed31373eedaa269ee200d80c1d259e35d432db53ac140c7a282af488993beb40d8bc1bb6c174e5a6b2c910d4
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-11-25 10:59:49

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: SmartTV Setup
FileVersion:
LegalCopyright:
ProductName: SmartTV
ProductVersion:
Translation: 0x0000 0x04b0

Backdoor.TVRat.Dropper also known as:

BkavW32.AIDetectMalware
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
Cylanceunsafe
ZillyaTrojan.Injuke.Win32.37801
K7AntiVirusTrojan ( 005722fe1 )
AlibabaTrojanDropper:Win32/Injuke.2ca8269e
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
APEXMalicious
KasperskyTrojan.Win32.Injuke.jntx
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Injuke.Fwnw
SophosGeneric Reputation PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1332570
DrWebTrojan.Siggen22.15776
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojan.Ekstak.ciey
VaristW32/Trojan.KPAM-1505
AviraHEUR/AGEN.1332570
KingsoftWin32.Trojan.Injuke.a
MicrosoftTrojan:Win32/Convagent!ml
ZoneAlarmTrojan.Win32.Injuke.jntx
GDataWin32.Trojan.Agent.9A00CJ
AhnLab-V3Trojan/Win.DownloadAssistant.R621621
McAfeeArtemis!70EE75C5BEE0
MalwarebytesBackdoor.TVRat.Dropper
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CKP23
MaxSecureTrojan.Malware.220939732.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor.TVRat.Dropper?

Backdoor.TVRat.Dropper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment