Backdoor

How to remove “Backdoor:Win32/Vawtrak.A”?

Malware Removal

The Backdoor:Win32/Vawtrak.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Vawtrak.A virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • PlugX
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristics of Vawtrak / Neverquest malware.
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Vawtrak.A?


File Info:

crc32: C6AC1C51
md5: 11ebb20cc8e6119d1072063e0533c529
name: 11EBB20CC8E6119D1072063E0533C529.mlw
sha1: bef1a1c06798463870a4b920cc3f9b8c2b98305d
sha256: be14ddc5f1f787bf9dba72eee9f233b287aabde5276e23c4ce9087910a96ee4e
sha512: acacad5f35749ddbf756788fa313fa4e506de98bc925da16c3efb52122dcecd488d7e0a3dbc7f452a9dc6378b0ee19e73e71f48613edc1544b63e342b95227da
ssdeep: 6144:uXFSNuqsmwYJh+yVmpHOTtCRXBddE9KQ5PcyU60aa31LFTFLklLveN4prbp:3IqHJh+ywYTezVQ5PSVaU1BFLklLGO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: colorcpl
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Microsoft Color Control Panel
OriginalFilename: colorcpl.exe
Translation: 0x0409 0x04b0

Backdoor:Win32/Vawtrak.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.13574
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Vawtrack.F4
McAfeeArtemis!11EBB20CC8E6
CylanceUnsafe
ZillyaTrojan.Papras.Win32.1890
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Papras.0ffcbac0
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.cc8e61
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Papras.DT
APEXMalicious
AvastWin32:Crypt-RWF [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.GenericKD.43367153
NANO-AntivirusTrojan.Win32.Stealer.dnqfjg
MicroWorld-eScanTrojan.Ransom.GenericKD.43367153
TencentWin32.Trojan.Generic.Dyqt
Ad-AwareTrojan.Ransom.GenericKD.43367153
SophosMal/Generic-R + Mal/Vawtrak-H
ComodoMalware@#rynvi2ujp011
BitDefenderThetaGen:NN.ZexaF.34692.zq0@aWkYWzci
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_DYER.BME
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.11ebb20cc8e6119d
EmsisoftTrojan.Ransom.GenericKD.43367153 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bjgqy
WebrootW32.Infostealer.Zeus
AviraHEUR/AGEN.1123584
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.E30383
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Vawtrak.A
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GenericKD.43367153
AhnLab-V3Trojan/Win32.Gen
Acronissuspicious
VBA32BScope.TrojanRansom.Reveton
MAXmalware (ai score=100)
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_DYER.BME
RisingBackdoor.Vawtrak!8.11D (CLOUD)
YandexTrojan.Agent!QhGlVpIB+30
IkarusTrojan.Agent
FortinetW32/Bedep.EP!tr
AVGWin32:Crypt-RWF [Trj]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Vawtrak.A?

Backdoor:Win32/Vawtrak.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment