Backdoor

How to remove “Backdoor.Win32.Buterat.fllr”?

Malware Removal

The Backdoor.Win32.Buterat.fllr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Buterat.fllr virus can do?

  • At least one process apparently crashed during execution
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
bookmyroom.pk
a.tomx.xyz

How to determine Backdoor.Win32.Buterat.fllr?


File Info:

crc32: 3FEDDAF8
md5: a38e156b5c7b337ffbde6cc1ddab1004
name: A38E156B5C7B337FFBDE6CC1DDAB1004.mlw
sha1: 8340937bfd1546988e036fa5a5b44337eea08466
sha256: 32c1ddede5ae571f4094c068bdd0f96b8c45f2d809379b90b6185d06354a786b
sha512: 71924eaa354424cfed6507bb8573399eaf82ac49af3f7a45e1407e10fe0de1cd1fa13d3232d723f19f43be109faed101ada3176aee350ef67209a22e3355d1ac
ssdeep: 6144:c/7w+dSj4riSrbC5hO0QYLJr2pYJGlyrdObec5TlJXfVEHfg7kNd9qKC2mUph:gW4mOb+JJOEzRal9VE8QnCVy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor.Win32.Buterat.fllr also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Encoder.5666
CAT-QuickHealRansom.Gen.A7
ALYacGen:Heur.Mint.Zard.40
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaBackdoor:Win32/Buterat.966bdaf6
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b5c7b3
SymantecRansom.TeslaCrypt
ESET-NOD32a variant of Win32/Filecoder.NHJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Buterat.fllr
BitDefenderGen:Heur.Mint.Zard.40
NANO-AntivirusTrojan.Win32.Buterat.ehstws
ViRobotBackdoor.Win32.Z.Buterat.430080
MicroWorld-eScanGen:Heur.Mint.Zard.40
TencentWin32.Backdoor.Buterat.Llra
Ad-AwareGen:Heur.Mint.Zard.40
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.AmGfaGInANhi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPBEE.A
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.a38e156b5c7b337f
EmsisoftGen:Heur.Mint.Zard.40 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Buterat.fd
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2ADC95D
KingsoftWin32.Hack.Buterat.fl.(kcloud)
MicrosoftRansom:Win32/Enckerbee
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Mint.Zard.40
McAfeeArtemis!A38E156B5C7B
MAXmalware (ai score=100)
VBA32Backdoor.Buterat
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPBEE.A
YandexBackdoor.Buterat!+SfrRZqCFTM
IkarusBackdoor.Buterat
FortinetW32/Filecoder.NHJ!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Win32.Buterat.fllr?

Backdoor.Win32.Buterat.fllr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment