Backdoor

How to remove “Backdoor:Win32/Xtrat.AC”?

Malware Removal

The Backdoor:Win32/Xtrat.AC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Xtrat.AC virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Creates known XtremeRAT mutexes

Related domains:

rfefef.duckdns.org

How to determine Backdoor:Win32/Xtrat.AC?


File Info:

crc32: B54AE422
md5: 0394db81257ce589a1019605c93cdf80
name: ENTREGA-DE-SOPORTES-PAGO-PSE-REALIADO-EXITOSAMENTE-IMG.AVW-2323425235-235235325232-5253257.exe
sha1: 7dbd22f4a77a1570c323c1954bbeea71a1da225c
sha256: 0e6464c8f4b60eff44a75b6c5f74efe1fa607fbd267d3ea80442f95f33625407
sha512: a17131611bf238b060383cff1760797f2144064de0ec98976579190f95bcc8717bb69657b0229a2150f81fbad6c0825f89c9c2cd9dd6e995fa7d7d44298cb5c6
ssdeep: 12288:Otb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaJjOLyOJSpq6A:Otb20pkaCqT5TBWgNQ7aZOXYpq6A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Backdoor:Win32/Xtrat.AC also known as:

MicroWorld-eScanGen:Variant.Strictor.168106
CAT-QuickHealBackdoor.Xtrat
McAfeeArtemis!0394DB81257C
MalwarebytesTrojan.Injector.AutoIt
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
TrendMicroTROJ_GEN.R002C0DGO18
CyrenW32/Trojan.JTIR-3909
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002C0DGO18
AvastWin32:Trojan-gen
GDataGen:Variant.Strictor.168106
KasperskyTrojan.Win32.Autoit.fld
BitDefenderGen:Variant.Strictor.168106
NANO-AntivirusTrojan.Win32.Autoit.ffrhoj
ViRobotTrojan.Win32.Z.Strictor.1105920
AegisLabTroj.W32.Autoit!c
TencentWin32.Trojan.Autoit.Eoi
Ad-AwareGen:Variant.Strictor.168106
SophosMal/Generic-S
F-SecureGen:Variant.Strictor.168106
DrWebTrojan.DownLoader6.34128
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Strictor.168106 (B)
IkarusTrojan.Win32.Injector
AviraTR/Autoit.fkvqw
Endgamemalicious (high confidence)
ArcabitTrojan.Strictor.D290AA
ZoneAlarmTrojan.Win32.Autoit.fld
MicrosoftBackdoor:Win32/Xtrat.AC
AhnLab-V3Trojan/Win32.Scar.C1740631
ALYacGen:Variant.Strictor.168106
MAXmalware (ai score=89)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.DJG
SentinelOnestatic engine – malicious
FortinetAutoIt/Injector.DJG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.4a77a1
Paloaltogeneric.ml
CrowdStrikemalicious_confidence_80% (D)
Qihoo-360Win32/Trojan.524

How to remove Backdoor:Win32/Xtrat.AC?

Backdoor:Win32/Xtrat.AC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment