Backdoor

Backdoor.Win32.Xaparo removal

Malware Removal

The Backdoor.Win32.Xaparo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Xaparo virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Xaparo?


File Info:

crc32: 2C330675
md5: 7631d5cdcb0f2cf0cc603bd62a441e84
name: 7631D5CDCB0F2CF0CC603BD62A441E84.mlw
sha1: 0c8f52d2ee8766b77bb8ba0bc7f9bd7374e49b8c
sha256: 3e8962da569e1d2ab460b1713859a54d0f8f930a2b5113c95d109e94f231ecb0
sha512: 87586c2e459080638cb4b0465af8d70cdeec94de1215cc753cadaa449e6063068878782b315acf81baeb45f59c16d706da8db2fa03ed5e7e866576f3f45a7d60
ssdeep: 98304:XDkLSQ9e8vgIkbuTxuENpzYe84uq5oC0nKx/pXEle:zkeKe81kK1pzR5x/Ke
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) 2019 Tomsk, Inc.
InternalName: DeskRoll.exe
FileVersion: 2.8.2.52
CompanyName: Tomsk, Inc.
ProductName: DeskRoll Remote Desktop
ProductVersion: 2.8.2.52
FileDescription: DeskRoll Remote Desktop
OriginalFilename: DeskRoll.exe
Translation: 0x0409 0x04b0

Backdoor.Win32.Xaparo also known as:

MicroWorld-eScanTrojan.GenericKD.35817820
FireEyeTrojan.GenericKD.35817820
McAfeeArtemis!7631D5CDCB0F
SangforMalware
BitDefenderTrojan.GenericKD.35817820
K7GWSpyware ( 0055cb2e1 )
CyrenW32/Trojan.SOOC-7691
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Spy.Agent.PVY
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Xaparo.gen
RisingTrojan.MalCert!1.D079 (CLASSIC)
Ad-AwareTrojan.GenericKD.35817820
SophosMal/Generic-S
ComodoMalware@#2qmjecifidroy
F-SecureTrojan.TR/Spy.Agent.wizne
DrWebBackDoor.Rat.275
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.35817820 (B)
AviraTR/Spy.Agent.wizne
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA3E
ArcabitTrojan.Generic.D222895C
ZoneAlarmHEUR:Backdoor.Win32.Xaparo.gen
GDataWin32.Backdoor.Parallax.G9MEJV
CynetMalicious (score: 85)
MAXmalware (ai score=87)
IkarusTrojan-Spy.Agent
FortinetW32/Agent.PVY!tr.spy
AVGFileRepMalware
Qihoo-360Win32/Backdoor.ed6

How to remove Backdoor.Win32.Xaparo?

Backdoor.Win32.Xaparo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment