Backdoor

Backdoor.Win32.Xaparo.mf malicious file

Malware Removal

The Backdoor.Win32.Xaparo.mf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Xaparo.mf virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Xaparo.mf?


File Info:

crc32: E92CA018
md5: e1104876ebb32f85d47d8b477eea655b
name: E1104876EBB32F85D47D8B477EEA655B.mlw
sha1: 021341b0025363363982cd57afe27451eb9774e3
sha256: 6f8fc539952555b057adf7810aca782a29f8f624e1d46a0f4732db3763130725
sha512: 73601b1f7b165b03ecb1512c56fbbdc9600153d950ac668a937650ac0e65ab8bd03a4112c61b35b28909e0196ab415e0972eca8cbb456f7f07b62109242635aa
ssdeep: 49152:EMCjldY2S7LVEl0myvU9WrPC+X8zybKjS5fyu9KkmqEj/wf779WkXHqXWXP:AjqSV7WrPC08uPKkSwf7DHqXWf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2020 philandro Software GmbH
FileVersion: 6.1.0.0
CompanyName: philandro Software GmbH
ProductName: AnyDesk
ProductVersion: 6.1
FileDescription: AnyDesk
Translation: 0x0409 0x04e4

Backdoor.Win32.Xaparo.mf also known as:

MicroWorld-eScanTrojan.GenericKD.36380109
Qihoo-360Win32/Backdoor.Generic.HgIASPUA
McAfeeArtemis!E1104876EBB3
SangforTrojan.Win32.Ymacco.AA22
K7AntiVirusTrojan ( 005781aa1 )
BitDefenderTrojan.GenericKD.36380109
K7GWTrojan ( 005781aa1 )
ArcabitTrojan.Generic.D22B1DCD
CyrenW32/Trojan.XTMU-6815
SymantecTrojan.Gen.MBT
AvastFileRepMalware
KasperskyBackdoor.Win32.Xaparo.mf
AlibabaBackdoor:Win32/Xaparo.a67b9bc4
ViRobotTrojan.Win32.Z.Xaparo.5503976
RisingBackdoor.Xaparo!8.11758 (CLOUD)
Ad-AwareTrojan.GenericKD.36380109
SophosMal/Generic-S
ComodoMalware@#fgfqv864wwg4
F-SecureBackdoor.BDS/RAT.fvfwd
DrWebBackDoor.Rat.327
TrendMicroTROJ_FRS.VSNTBN21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36380109
EmsisoftMalCert.A (A)
IkarusTrojan.Win32.Gencbl
JiangminBackdoor.Xaparo.cx
WebrootW32.Trojan.Gen
AviraBDS/RAT.fvfwd
MAXmalware (ai score=85)
KingsoftWin32.Hack.Xaparo.mf.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA6F
ZoneAlarmBackdoor.Win32.Xaparo.mf
GDataTrojan.GenericKD.36380109
CynetMalicious (score: 85)
ALYacBackdoor.RAT.Parallax
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ESET-NOD32Win32/Spy.Agent.PVY
TrendMicro-HouseCallTROJ_FRS.VSNTBN21
TencentWin32.Backdoor.Xaparo.Agai
FortinetW32/GenCBL.ZF!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Backdoor.Win32.Xaparo.mf?

Backdoor.Win32.Xaparo.mf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment