Backdoor

About “Backdoor.TVRat.Dropper” infection

Malware Removal

The Backdoor.TVRat.Dropper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TVRat.Dropper virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor.TVRat.Dropper?


File Info:

name: 6E29FA4BCBEED83AA915.mlw
path: /opt/CAPEv2/storage/binaries/b6acd4e559fc503fffad75e3a6a20b9392d32a8a963c395f56f7a09d8e6bb886
crc32: 46094047
md5: 6e29fa4bcbeed83aa9159221f9724fdc
sha1: f86e6ad5d9057484e6056625235c65f31e1d69f3
sha256: b6acd4e559fc503fffad75e3a6a20b9392d32a8a963c395f56f7a09d8e6bb886
sha512: 4d75afde52fc8961a0e6df57404d36e3c9d8bd8b6b30863c380448b239e3a4e9713b89142d7e4d419324c9830cfc376e716d4a6d7fb128a91acd95a213a4da1e
ssdeep: 98304:TpIgPP8GeU9MuTi0yaYobgazVeL2/CJyc6uCXEInqwiW8Ysqwl:1IgP99Mu25aBgazVeSRc6uCXfiW8YsX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E16330105E2C473E58990B6AE8C6794563B76990FA5F2ACF3FC8BF41FE1A1214267F4
sha3_384: d125e52214e41f2e51d73209df696a0938a50e13de77cea3977ba03700c06c2c8fb1439f496cd4d691a1e342e8cc1778
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-03-24 11:49:43

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Color Point Setup
FileVersion:
LegalCopyright:
ProductName: Color Point
ProductVersion:
Translation: 0x0000 0x04b0

Backdoor.TVRat.Dropper also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!6E29FA4BCBEE
Cylanceunsafe
SangforTrojan.Win32.Agent.Vq23
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0CCO24
KasperskyTrojan.Win32.Ekstak.awtah
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Eplw
F-SecureHeuristic.HEUR/AGEN.1373347
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1373347
VaristW32/Trojan.MBYK-2189
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.awtah
GDataWin32.Backdoor.Bodelph.TN4C93
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Malware-gen.C5604686
MalwarebytesBackdoor.TVRat.Dropper
PandaTrj/Chgt.AD
IkarusTrojan.Win32.Crypt
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[dropper]:Win/Ekstak.awtah

How to remove Backdoor.TVRat.Dropper?

Backdoor.TVRat.Dropper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment