Backdoor Trojan

Trojan.Backdoor.PVA removal

Malware Removal

The Trojan.Backdoor.PVA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Backdoor.PVA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Enumerates running processes
  • A process created a hidden window
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • CAPE detected the QakBot malware family
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Backdoor.PVA?


File Info:

name: E4DBD41B04B1F0BE069B.mlw
path: /opt/CAPEv2/storage/binaries/85617e6bd2b4cba57d395f742f49cca1f674e392b2451259de17b750af6b1a2f
crc32: 5BAFCCBD
md5: e4dbd41b04b1f0be069b09af974fcf71
sha1: 0899b9a9b46aeec47b2153cb74571299149d5e9b
sha256: 85617e6bd2b4cba57d395f742f49cca1f674e392b2451259de17b750af6b1a2f
sha512: 3eb590fdd1d7516d6d3497c3eedaf869849902026316dd5f13e71caee15afb8d6f4bbef09c24da3c559f7f30c188c48bab3ee0b17b7c7db9b729eb50a3e728af
ssdeep: 12288:JrRLE0GEObdQEg3V0QREE5wOtOBUfkRbCSRnUYY0BTQEWK:JfGDxQXurItqUc3Rni0BTV5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1920502A036628931CA17A4BA6974D33079A861421F3743FFB26106FD4AC25F27DBD64F
sha3_384: 0adf28aa4dcb349c3558085764b6c6bd6ab66cd6e1fb8e8fc39e5e59847a9e5a2c6886323d19368ce6786a9068d9267d
ep_bytes: e8b5380000e91efeffff8bff558bec56
timestamp: 2019-02-22 06:18:07

Version Info:

0: [No Data]

Trojan.Backdoor.PVA also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Qbot.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Backdoor.PVA
McAfeeGenericATG-FACX!E4DBD41B04B1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1597683
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Kryptik.c041a41e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b04b1f
BitDefenderThetaGen:NN.ZexaF.34294.0yW@aiatRZji
SymantecW32.Qakbot!gm
ESET-NOD32a variant of Win32/Kryptik.GPZN
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Qbot.ahwy
BitDefenderTrojan.Backdoor.PVA
NANO-AntivirusTrojan.Win32.Qbot.fnicjs
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114d9315
Ad-AwareTrojan.Backdoor.PVA
SophosMal/Generic-R + Mal/Qbot-R
ComodoMalware@#nw3jl7fagydl
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.EMOTET.SMAL07A.hp
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.e4dbd41b04b1f0be
EmsisoftTrojan.Backdoor.PVA (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Backdoor.PVA
JiangminBackdoor.QBot.jl
AviraHEUR/AGEN.1116161
Antiy-AVLTrojan/Generic.ASMalwS.2AA6A60
ArcabitTrojan.Backdoor.PVA
MicrosoftTrojan:Win32/Occamy.C85
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3036713
Acronissuspicious
VBA32BScope.Backdoor.Qbot
ALYacTrojan.Backdoor.PVA
MAXmalware (ai score=87)
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMAL07A.hp
IkarusTrojan.Qbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.280938!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Backdoor.PVA?

Trojan.Backdoor.PVA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment