Backdoor

Backdoor.TVRat.Dropper (file analysis)

Malware Removal

The Backdoor.TVRat.Dropper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TVRat.Dropper virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor.TVRat.Dropper?


File Info:

name: 3756EA33AFDE41E54267.mlw
path: /opt/CAPEv2/storage/binaries/234c526f5d5e95913ec1dff665ae65e2bcee0b1fdb19453b7c25c8bc52a9b492
crc32: 34D76CD6
md5: 3756ea33afde41e54267b33ae939ae14
sha1: 007b2e117af4abab05f9e1511a67e7a85c0f5510
sha256: 234c526f5d5e95913ec1dff665ae65e2bcee0b1fdb19453b7c25c8bc52a9b492
sha512: 76f80725e7a5071049c2c5a84e696085e8a17e017c7171cd005f6ef02bc79a9b7238c1237bad4b93332faf35b22719c8f6c89e1c78ff3fd76e83016bd30a22a2
ssdeep: 98304:hgQPUU0pRh3USOjmYxdyg2ACm8s5D4eM2nHjnxgiJmtMJQ71qJRI8MMMhWM:GnfpvESFYxQACu5MeBHjm6mqiYDIyMAM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17126331A1890D47AD873ADF0A6B0A855ED743D45FE70F9093EECD497A3B3102588EDA3
sha3_384: afce81c920a0f2df70a98de664de2ae889a3734330106742523d08a5786b1bf7d713c118914a689478091f797a917ec9
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-02-16 02:44:57

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Audials Tunebite Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Backdoor.TVRat.Dropper also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanTrojan.Generic.35277000
FireEyeTrojan.Generic.35277000
SkyhighBehavesLike.Win32.BadFile.rc
McAfeeArtemis!3756EA33AFDE
Cylanceunsafe
SangforTrojan.Win32.Agent.Vw5a
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.8541cd31
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ekstak.avufr
BitDefenderTrojan.Generic.35277000
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Ftgl
EmsisoftTrojan.Generic.35277000 (B)
VIPRETrojan.Generic.35277000
SophosMal/Generic-S
IkarusTrojan.Win32.FakeAV
GDataWin32.Backdoor.Bodelph.2JARHI
ArcabitTrojan.Generic.D21A48C8
ZoneAlarmTrojan.Win32.Ekstak.avufr
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Agent.IIX.gen!Eldorado
AhnLab-V3Trojan/Win.Malware-gen.C5589662
ALYacTrojan.Generic.35277000
MalwarebytesBackdoor.TVRat.Dropper
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0DBG24
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Agent
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.TVRat.Dropper?

Backdoor.TVRat.Dropper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment