Backdoor

Backdoor:Win32/Trenk!rts removal

Malware Removal

The Backdoor:Win32/Trenk!rts is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Trenk!rts virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Detects VMware through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Trenk!rts?


File Info:

crc32: 13981479
md5: e03def716cbb89d96ed491b18b84e624
name: E03DEF716CBB89D96ED491B18B84E624.mlw
sha1: ede086949144142bd9c4551059e59e65b82c6e0c
sha256: f8a3574b81c6c424aa4f6cd73b9e02ee27ede2398a7fa31e029a0d0088d2c3d7
sha512: d12d2487b238258869c3b7670815a44e66853f3d6e0bbc9f15d122bb5563d0054327261deab98cbc1f4a0c357cc6f642d76fe449b1c02d96b90085f1692f672c
ssdeep: 768:HhI1t63nU5ZjoMefFNZEHM3WJneJsNMHBmw3bFZriVd2W+r/dD:UkMU9kM3WBeWN9w3Jmd2W+TdD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 1996-97 Microsoft Corp.
InternalName: VISDATA
FileVersion: 6.00.8168
CompanyName: Microsoft Corp.
ProductName: VisData
OLESelfRegister:
ProductVersion: 6.00.8168
OriginalFilename: VISDATA.exe
Translation: 0x0409 0x04b0

Backdoor:Win32/Trenk!rts also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.GZ.dm0@biag4Kmi
ALYacGen:Trojan.Heur.GZ.dm0@biag4Kmi
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusBackdoor ( 0010d2871 )
BitDefenderGen:Trojan.Heur.GZ.dm0@biag4Kmi
K7GWBackdoor ( 0010d2871 )
Cybereasonmalicious.16cbb8
BitDefenderThetaAI:Packer.04FECEA11F
CyrenW32/VBanti.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Inject-ABT [Trj]
KasperskyWorm.Win32.VBNA.b
AlibabaWorm:Win32/Bifrose.0b2bf7b8
NANO-AntivirusTrojan.Win32.VB.dexrzd
ViRobotBackdoor.Win32.Bifrose.61440.I
AegisLabTrojan.Win32.Generic.l4p9
Ad-AwareGen:Trojan.Heur.GZ.dm0@biag4Kmi
TACHYONBackdoor/W32.VB-Bifrose.61440
SophosML/PE-A + Troj/Bifrose-ZA
ComodoTrojWare.Win32.Autorun.JT@4zqndt
F-SecureTrojan.TR/Dropper.Gen
ZillyaBackdoor.Bifrose.Win32.22328
TrendMicroBKDR_BIFROSE.DXE
McAfee-GW-EditionBehavesLike.Win32.Generic.kh
FireEyeGeneric.mg.e03def716cbb89d9
EmsisoftGen:Trojan.Heur.GZ.dm0@biag4Kmi (B)
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.VBNA
MicrosoftBackdoor:Win32/Trenk!rts
ArcabitTrojan.Heur.GZ.E5C763
ZoneAlarmWorm.Win32.VBNA.b
GDataGen:Trojan.Heur.GZ.dm0@biag4Kmi
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E03DEF716CBB
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BIFROSE.DXE
RisingWorm.VBNA!8.2BE (CLOUD)
YandexBackdoor.Bifrose!RWH2JKWi7G8
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Backdoor
FortinetW32/Bifrose.BTWT!tr.bdr
AVGWin32:Inject-ABT [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Worm.5d0

How to remove Backdoor:Win32/Trenk!rts?

Backdoor:Win32/Trenk!rts removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment