Backdoor

Backdoor.TVRat.Generic malicious file

Malware Removal

The Backdoor.TVRat.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TVRat.Generic virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor.TVRat.Generic?


File Info:

name: 23752BBD6246CC39126C.mlw
path: /opt/CAPEv2/storage/binaries/74e728b639eac554232811bdfec06c12db40e8814993d284c7ad73225cabb575
crc32: 6A43239E
md5: 23752bbd6246cc39126c53af8273e6db
sha1: e72fda1b3b7ed17b9fb3b3967f35359d4d39bed7
sha256: 74e728b639eac554232811bdfec06c12db40e8814993d284c7ad73225cabb575
sha512: cbcd3bbc0a94bde50a13ae9d23cbeb29278a6e488cb9cc1ed96648da58ffcb3c8a0daf4ab8f0d67fd7093b0c2c65a4fd896e49afd89566db7a1671855f79bd50
ssdeep: 49152:oplCpvpLiub6pEpSSpwpalpyru0jDqiD/lXeFHPMHsMv+Cz:opspvpLipEpJpwp0pyrlvqiteMsMf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CA5CF522B8AB2EBC05F1478DC1FCF4AC5256EA26E20CE3BE55F7C1EAD327812149355
sha3_384: 707ca637f87de1932f47e3d61759d13e6a27c99e73bb3c7f677908f0947811584be3229db92d269cd6af4dd227d5e6b7
ep_bytes: 558bec6aff6858e34b0068107c4b0064
timestamp: 2020-03-23 16:26:11

Version Info:

0: [No Data]

Backdoor.TVRat.Generic also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.527297
FireEyeGeneric.mg.23752bbd6246cc39
SkyhighBehavesLike.Win32.Corrupt.vc
MalwarebytesBackdoor.TVRat.Generic
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005ae93b1 )
K7GWTrojan ( 005ae93b1 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HVSI
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Trojan.Win32.Ekstak
BitDefenderGen:Variant.Fragtor.527297
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Kryptik.Mqil
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1373002
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Fragtor.527297 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1373002
Kingsoftmalware.kb.a.987
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Win32.Ekstak
GDataGen:Variant.Fragtor.527297
GoogleDetected
McAfeeArtemis!23752BBD6246
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLKD!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Multi/Kryptik.HKNP

How to remove Backdoor.TVRat.Generic?

Backdoor.TVRat.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment