Backdoor

Should I remove “Backdoor:Win32/Coolvidoor.D”?

Malware Removal

The Backdoor:Win32/Coolvidoor.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Coolvidoor.D virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Coolvidoor.D?


File Info:

name: B47F20A134C422C4AF7E.mlw
path: /opt/CAPEv2/storage/binaries/f61e23dc02380685f4fe20ee7c8120164afd78f94090f47854a72cc634ae5a50
crc32: C9C6985A
md5: b47f20a134c422c4af7ea49059f8c6fa
sha1: 6a06a53cf0f38ad9ae74479b3cc7978e16ee4330
sha256: f61e23dc02380685f4fe20ee7c8120164afd78f94090f47854a72cc634ae5a50
sha512: 5f9b6acc9a190615c5adc5f7eef4205cc92995da76089da856ccd76e5724770b85a9a8bc86e8c78a7c8bc42c66c80185e2d880aafda5483dcfaeb566d55542b6
ssdeep: 6144:DB4srSnVIYiE1GD23X93pTiWxkGmGiRCbxDLLd9CtQSJNZafj9:DRYiE88XvYRadLd9CtQSpw9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168648E36FA80C537D1620B345C2AA2E99839BF612D38795B72E91F0C5E3D7C2791C792
sha3_384: 3a0231bdd42d615ae0743b82cb5e96d562d2bae4a3fbde209820127dd73dd001bf79fa36e7529bfd69c4d04bda20ee7e
ep_bytes: 558bec83c4e853565733c08945ec8945
timestamp: 2011-07-09 18:27:31

Version Info:

0: [No Data]

Backdoor:Win32/Coolvidoor.D also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.7810
MicroWorld-eScanGen:Variant.Buzy.4531
FireEyeGeneric.mg.b47f20a134c422c4
McAfeeArtemis!B47F20A134C4
CylanceUnsafe
ZillyaTrojan.Agent.Win32.148589
K7AntiVirusTrojan ( 7000000f1 )
AlibabaBackdoor:Win32/Coolvidoor.4de776d3
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.134c42
BitDefenderThetaGen:NN.ZelphiF.34062.tOW@a0yaIye
CyrenW32/Hupigon.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.AYS
TrendMicro-HouseCallTROJ_GEN.R002C0DKS21
ClamAVWin.Trojan.Agent-471544
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Buzy.4531
NANO-AntivirusTrojan.Win32.Agent.obblv
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Generic.Pepr
Ad-AwareGen:Variant.Buzy.4531
SophosMal/Generic-S
ComodoMalware@#38pvangkf8pzq
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DKS21
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
EmsisoftGen:Variant.Buzy.4531 (B)
GDataGen:Variant.Buzy.4531
JiangminTrojan/Agent.esvb
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.94802B
GridinsoftRansom.Win32.Gen.sa
MicrosoftBackdoor:Win32/Coolvidoor.D
CynetMalicious (score: 100)
ALYacGen:Variant.Buzy.4531
VBA32BScope.Backdoor.Delf
APEXMalicious
YandexTrojan.Agent!d9JLLe+erzI
IkarusBackdoor.Win32.Dokstormac
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NZYT!tr
AVGWin32:TrojanX-gen [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Backdoor:Win32/Coolvidoor.D?

Backdoor:Win32/Coolvidoor.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment