Backdoor

Backdoor:Win32/Coolvidoor.A removal

Malware Removal

The Backdoor:Win32/Coolvidoor.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Coolvidoor.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Coolvidoor.A?


File Info:

name: 4BAC6EF6ECF04AF3DFE9.mlw
path: /opt/CAPEv2/storage/binaries/4b324f81a593efa44ae8bc2272bd34153d517a74ed3d788bae7bd7348447f581
crc32: 8C6AEA42
md5: 4bac6ef6ecf04af3dfe978113c07e77c
sha1: 0bc6c1ecf4339fd45017a2cd453bb9326b411dd4
sha256: 4b324f81a593efa44ae8bc2272bd34153d517a74ed3d788bae7bd7348447f581
sha512: 4e78042b4faa727d338bfde5b08807d85e9d38afbc884a535b89f869b3136740920a19fe4f227e51e0e817da150f7e2a7c2dcf1ff9591dab868e29f854a3f58f
ssdeep: 6144:DuIN4z5mHUG7jo/dhQoacUAd7CBRlnOLy986mBWa:H4zqUGIBdu9nOB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181545D21F6C14477D1631A38AC1BBABD9939BB202D39645BB7E95E0C4D393C2BC18397
sha3_384: 3efb83ab52857de3d9a0d3b94daab0af90983a110f68285772963de9d316983aaa1dce3163277f0518d86cfa7b83c59b
ep_bytes: 558bec83c4f053b8d8ee4300e83b75fc
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Coolvidoor.A also known as:

Elasticmalicious (high confidence)
ClamAVWin.Trojan.Agent-111785
McAfeeGenericR-EOH!4BAC6EF6ECF0
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bbf3a1 )
K7GWTrojan ( 004bbf3a1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.GYE
CyrenW32/Trojan.MUAR-8174
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Coolvidoor.AP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.gen
NANO-AntivirusTrojan.Win32.Coolvidoor.cwlvyn
AvastWin32:Klone-RB [Trj]
ComodoMalware@#kn8tj1rsriqc
DrWebTrojan.DownLoader6.21938
ZillyaTrojan.Agent.Win32.24266
TrendMicroBKDR_COOLVIDOO.Y
McAfee-GW-EditionBehavesLike.Win32.Sytro.dh
FireEyeGeneric.mg.4bac6ef6ecf04af3
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.bmrw
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2D
MicrosoftBackdoor:Win32/Coolvidoor.A
ViRobotTrojan.Win32.Agent.299008.E
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R114439
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.3958427632
TrendMicro-HouseCallBKDR_COOLVIDOO.Y
RisingBackdoor.Coolvidoor!8.115C (TFE:5:pn7dhj86GXB)
YandexTrojan.GenAsa!XCiIBTngf3Q
IkarusTrojan-Dropper.Win32.Typic
MaxSecureTrojan.Malware.782555.susgen
FortinetW32/Coolvidoor.Y!tr
BitDefenderThetaGen:NN.ZelphiF.34698.sGX@a4jjTwb
AVGWin32:Klone-RB [Trj]
Cybereasonmalicious.6ecf04
PandaGeneric Malware

How to remove Backdoor:Win32/Coolvidoor.A?

Backdoor:Win32/Coolvidoor.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment