Backdoor

Should I remove “Backdoor.Win32.TeviRat.lb”?

Malware Removal

The Backdoor.Win32.TeviRat.lb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.TeviRat.lb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.TeviRat.lb?


File Info:

name: 46E0116E544B4F87E85B.mlw
path: /opt/CAPEv2/storage/binaries/0b7bea3f7ae6cc917cbf4106799134bc8f6cf7bab7c7718bb4e543ccfc64bb2c
crc32: 4D029CA2
md5: 46e0116e544b4f87e85b63ccdc279304
sha1: 1129f954c61536e70204bda928cb62f374496ddb
sha256: 0b7bea3f7ae6cc917cbf4106799134bc8f6cf7bab7c7718bb4e543ccfc64bb2c
sha512: db4156e38b19990fc3881f2c6bf31e8b27a7288112a268c3044b22843c56b2509fd8d6e73dccf60087ac818d8b0cc15b383ba2350cbefd7cd4b3dbe75299ee18
ssdeep: 49152:dy1QmKlbs+OEVDsI10qbhm3cPnL8U34fb1DTF3SxqZKhOnRrqv:o1Qm43OODnpvnL8iChvwxJMnRrG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18CC52367E6D58130DC7B1B72A8668AC4053B7C937D26094D328EFA0D37336817E4BB66
sha3_384: fe278aedc4e143a90a2e08bb4fe48fcfa470313491cf10d86e3dc5dfe57822471ed1a81e0373bd5389f3148638104982
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Genie-Soft
FileDescription: EditPlus Text Editor Setup
FileVersion:
LegalCopyright:
ProductName: EditPlus Text Editor
ProductVersion: 5.2.2278.1
Translation: 0x0000 0x04b0

Backdoor.Win32.TeviRat.lb also known as:

LionicTrojan.Win32.TeviRat.m!c
CynetMalicious (score: 99)
FireEyeTrojan.GenericKD.38094949
ALYacTrojan.GenericKD.38094949
CylanceUnsafe
SangforBackdoor.Win32.TeviRat.lb
K7AntiVirusTrojan-Downloader ( 0056c4991 )
AlibabaBackdoor:Win32/TeviRat.6ff4bd3c
K7GWTrojan-Downloader ( 0056c4991 )
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/CrthRazy.R
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyBackdoor.Win32.TeviRat.lb
BitDefenderTrojan.GenericKD.38094949
MicroWorld-eScanTrojan.GenericKD.38094949
Ad-AwareTrojan.GenericKD.38094949
EmsisoftTrojan.GenericKD.38094949 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.Kryptik.HF8IVA
JiangminTrojan.Ekstak.bazz
AviraHEUR/AGEN.1138873
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Crthrazy.2572731
MicrosoftTrojan:MSIL/DataStealer.MK!MSR
AhnLab-V3Trojan/Win.Generic.C4787581
McAfeeArtemis!46E0116E544B
MAXmalware (ai score=80)
VBA32Backdoor.TeviRat
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R03BC0WKP21
FortinetRiskware/CrthRazy
AVGWin32:AdwareX-gen [Adw]

How to remove Backdoor.Win32.TeviRat.lb?

Backdoor.Win32.TeviRat.lb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment