Backdoor

Backdoor:Win32/Taroca.A removal instruction

Malware Removal

The Backdoor:Win32/Taroca.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Taroca.A virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Taroca.A?


File Info:

name: 07B40312047F204A2C1F.mlw
path: /opt/CAPEv2/storage/binaries/253a704acd7952677c70e0c2d787791b8359efe2c92a5e77acea028393a85613
crc32: A0B4E01E
md5: 07b40312047f204a2c1fbd94fba6f53b
sha1: 59d7aaff5e8cba285ba18c67473cb578c64c3c7d
sha256: 253a704acd7952677c70e0c2d787791b8359efe2c92a5e77acea028393a85613
sha512: c1aa3ed7f1bd044b31c1b629b5bdc2b9049c8d126c5fbdbb5c9ea0ec0324ffde76419c22c72cda3d3b2bdc3afa1b9df9a65493338be159aabad99889afc42f4c
ssdeep: 768:Xlz7Lhj/LSD7CENNfvSOdNjbyocZ01W3ybBId2l:9NzLqxSOdpbyjZYRl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF238D137CDB80B7DD2632B006AA4F35577B954A02268BD7DF60DDA92C32671CE3A342
sha3_384: 2f9aa6ce94d78b81e21e5ef6dd24d4ade68ff6c22c0174ca7be3c3fb36f45444aaff2ac5cad38dcb3dd59ab66f4750c4
ep_bytes: 558bec6aff6880914000681064400064
timestamp: 2013-12-10 08:36:32

Version Info:

0: [No Data]

Backdoor:Win32/Taroca.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tinba.trUS
MicroWorld-eScanGen:Variant.Doina.21113
ClamAVWin.Trojan.OrcaRAT-1
MalwarebytesMalware.AI.3599174008
ZillyaTrojan.Leouncia.Win32.22
SangforBackdoor.Win32.Taroca.Va1c
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Tinba.3468bbe0
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2047f2
ArcabitTrojan.Doina.D5279
BitDefenderThetaGen:NN.ZexaF.36350.dmW@a0N6F0i
VirITBackdoor.Win32.Generic.AYQX
CyrenW32/Trojan.MLDT-6412
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Leouncia.D
TrendMicro-HouseCallBKDR_TAROCA.PBH
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Tinba.akch
BitDefenderGen:Variant.Doina.21113
NANO-AntivirusTrojan.Win32.Tinba.gcxqoj
AvastWin32:Malware-gen
TencentWin32.Trojan.Injected.Rnit
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1341958
VIPREGen:Variant.Doina.21113
TrendMicroBKDR_TAROCA.PBH
McAfee-GW-EditionBackDoor-FBNQ!07B40312047F
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.07b40312047f204a
EmsisoftGen:Variant.Doina.21113 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1341958
Antiy-AVLTrojan/Win32.Tinba
XcitiumMalware@#27cyy49xgpr6e
MicrosoftBackdoor:Win32/Taroca.A
ZoneAlarmTrojan.Win32.Tinba.akch
GDataGen:Variant.Doina.21113
GoogleDetected
AhnLab-V3Backdoor/Win.TrojanHorse.C5464262
VBA32BScope.Trojan.Tinba
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
APEXMalicious
RisingBackdoor.Taroca!8.5A87 (TFE:5:uteu6IFHMGD)
MaxSecureTrojan.Malware.7734580.susgen
FortinetW32/BDoor.FBNQ!tr.bdr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Taroca.A?

Backdoor:Win32/Taroca.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment