Backdoor

How to remove “Backdoor.TVRat”?

Malware Removal

The Backdoor.TVRat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TVRat virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

widolapsed.info

How to determine Backdoor.TVRat?


File Info:

crc32: F08234C0
md5: 5efc68abd7fec415e34980d95a06a66a
name: 5EFC68ABD7FEC415E34980D95A06A66A.mlw
sha1: 34b243a0b3e322b8983b528caa5849395360a91d
sha256: 0f655a8ac0d7fdc7ac44fdd9799129848faf9c73bfa0e108fd903de439447232
sha512: 92aa33884c54bdb2608994b3e4c9b0909b002a38344bae2b4fb01c9a713542cf8a51684a0e3d614730340a995bb918dedb5e4c801ba9e3afa834399f38232079
ssdeep: 49152:tMvOJUaiTddo110aPENuUn/vrmUJjefHj9uDd:tHjiTvLn3rb4jkd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.TVRat also known as:

K7AntiVirusSpyware ( 005818cb1 )
DrWebTrojan.Siggen15.3031
CynetMalicious (score: 99)
CAT-QuickHealTrojanSpy.Agent
ALYacTrojan.Agent.Wacatac
CylanceUnsafe
ZillyaTrojan.Convagent.Win32.6195
CrowdStrikewin/malicious_confidence_80% (D)
K7GWSpyware ( 005818cb1 )
CyrenW32/Trojan.YELI-1173
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Spy.Pavica.FS
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan-Spy.Win32.Agent.jzca
BitDefenderTrojan.Autoruns.GenericKD.46875169
NANO-AntivirusTrojan.Win32.TeamViewer.jaczqd
MicroWorld-eScanTrojan.Autoruns.GenericKD.46875169
Ad-AwareTrojan.Autoruns.GenericKD.46875169
SophosMal/Generic-R
ComodoMalware@#2ja81qw11xfee
TrendMicroTROJ_FRS.VSNW1EH21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.Autoruns.GenericKD.46875169
EmsisoftMalCert.A (A)
WebrootW32.Malware.Gen
AviraTR/Spy.Pavica.gkqib
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/CryptInject!MSR
ArcabitTrojan.Autoruns.Generic.D2CB4221
GDataTrojan.Autoruns.GenericKD.46875169
McAfeeArtemis!5EFC68ABD7FE
MAXmalware (ai score=81)
VBA32Backdoor.TeamViewer
MalwarebytesBackdoor.TVRat
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.VSNW1EH21
IkarusTrojan-Spy.Agent
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Backdoor.TVRat?

Backdoor.TVRat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment