Backdoor

Backdoor.TVRat.Generic removal instruction

Malware Removal

The Backdoor.TVRat.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TVRat.Generic virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.TVRat.Generic?


File Info:

name: F7133F6CB44E9C2F045E.mlw
path: /opt/CAPEv2/storage/binaries/ed27f66fb1621658ab34a78d0f3a5e906e5d608ab836f277cd938afd6fa4d236
crc32: 44F3D760
md5: f7133f6cb44e9c2f045eee1550251879
sha1: f0407dcf7d1232ca1d6f2734c8c83d13dbab2513
sha256: ed27f66fb1621658ab34a78d0f3a5e906e5d608ab836f277cd938afd6fa4d236
sha512: e8f56a7a4d00f75c0a7862c48dc73d3be732c8ebc479a5f760d800ac2c483a9f049b3d192c87083ab0157fde2c962aee47e8f09aedf5832ede2ed8556b177cd9
ssdeep: 196608:0DsOmTw4nLxr6riBdvCU4wRPN3fgqGUa5sd:UsOmUUrK6dvC1aN3fVa5Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E96337360718D75EC9A96F90608E442C517A33587F448C897334ABF6F6E632E862BC7
sha3_384: 62abf3581ed8d8b6a77a2c96571d3217ea1555d3ae829b1aa572d18f25c783be2f6afcced62a031cc1d671abb6c275a9
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2023-12-02 00:49:15

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: XRECODE 3 Setup
FileVersion:
LegalCopyright:
ProductName: XRECODE 3
ProductVersion:
Translation: 0x0000 0x04b0

Backdoor.TVRat.Generic also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injuke.16!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen22.59937
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!F7133F6CB44E
MalwarebytesBackdoor.TVRat.Generic
ZillyaTrojan.Injuke.Win32.38023
AlibabaTrojanDropper:Win32/Injuke.96a0aa9b
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.Injuke.kkgf
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Injuke.Ewnw
F-SecureHeuristic.HEUR/AGEN.1332570
TrendMicroTROJ_GEN.R002C0DLD23
SophosMal/Generic-S
JiangminTrojan.Ekstak.cihn
AviraHEUR/AGEN.1332570
ViRobotTrojan.Win.Z.Agent.8702617.AQ
ZoneAlarmTrojan.Win32.Injuke.kkgf
GDataWin32.Trojan.Agent.57F1XT
AhnLab-V3Trojan/Win.DownloadAssistant.R622897
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DLD23
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor.TVRat.Generic?

Backdoor.TVRat.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment