Backdoor

What is “Backdoor.Win32.TeviRat.kg”?

Malware Removal

The Backdoor.Win32.TeviRat.kg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.TeviRat.kg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Backdoor.Win32.TeviRat.kg?


File Info:

name: 7BC35510990CE54B697B.mlw
path: /opt/CAPEv2/storage/binaries/c2502120edc72f3a144d655e7d7a403f5f0f4212e673eb618da7701827a59ded
crc32: 4BAE51B7
md5: 7bc35510990ce54b697bd67fb89e1166
sha1: 51edfa7995f62afef0b5dd8e51fb8acb3fe52a47
sha256: c2502120edc72f3a144d655e7d7a403f5f0f4212e673eb618da7701827a59ded
sha512: 59ebbb273259a9719af243d3f262ae0147cb37a9d931390cac294cdfe6382ec84c232a78cfa071388ce2c5fc1a764d09f9875afbe22a4d1b46e83388c4f080ce
ssdeep: 49152:2csQ6Q6nGP3PpXqWM68Ifx115ZJ5ap4x0LXdN02WQCVvi6OcEJ4lOxP0i:21QT6n03Ppxf8IfvtujdPCxi6IP3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187F5F123B288A53DC45D27320A73D1A059FBBA6DE8176F1632F0D68DDF211C14E3BA65
sha3_384: f3a4a57e6ab918efdcff1d74c83e5b53afef3208f21d238543571c7403275832365178a231efe6b0f8485e8b3196a360
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Cot Logic
FileDescription: CotList Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: CotList
ProductVersion: 0.8.0.9
Translation: 0x0000 0x04b0

Backdoor.Win32.TeviRat.kg also known as:

LionicTrojan.Win32.TeviRat.m!c
MicroWorld-eScanTrojan.GenericKD.47460905
FireEyeTrojan.GenericKD.47460905
ALYacTrojan.GenericKD.47460905
K7GWTrojan ( 0057e05e1 )
K7AntiVirusTrojan ( 0057e05e1 )
CyrenW32/Addrop.L.gen!Eldorado
ESET-NOD32Win32/TrojanDropper.Addrop.DH
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.TeviRat.kg
AlibabaBackdoor:Win32/TeviRat.8f42e688
AvastWin32:Trojan-gen
EmsisoftTrojan.GenericKD.47460905 (B)
SophosMal/Generic-S
AviraHEUR/AGEN.1143627
ArcabitTrojan.Generic.D2D43229
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C4786019
McAfeeArtemis!7BC35510990C
MAXmalware (ai score=80)
MalwarebytesAdware.DownloadAssistant
TencentWin32.Backdoor.Tevirat.Alix
IkarusTrojan-Dropper.Win32.Addrop
FortinetW32/Addrop.DH!tr
AVGWin32:Trojan-gen

How to remove Backdoor.Win32.TeviRat.kg?

Backdoor.Win32.TeviRat.kg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment