Backdoor

Backdoor:Win32/Oderoor!A information

Malware Removal

The Backdoor:Win32/Oderoor!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Oderoor!A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Oderoor!A?


File Info:

name: 50778F934F108C6971FA.mlw
path: /opt/CAPEv2/storage/binaries/c56d4af984b562b44f9520575600600f8150b4f8543af0b3279892928bb9ae48
crc32: 42FB80B3
md5: 50778f934f108c6971fa637294e613a6
sha1: b9ee265bbe1dc7c63df2e472575d9a053f0dd7be
sha256: c56d4af984b562b44f9520575600600f8150b4f8543af0b3279892928bb9ae48
sha512: 00f52dee0e0b7632d6b9ab3cb7b307399e16fea59206a1cbcec08a31aa266320dab1d54d59b118c774bbc3ff1cc7319894aef7c1fc2025b3faa74bd7b31f185d
ssdeep: 3072:q3kXW9B9JLG81FNXkfrxAALAp5+YpIZPBw5A9JxN:q3v9RLG81FBkfrxAAknIrpDN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18CD3D03C858CF44BF2F9C9F4DD7BC9221206748FFAAA1654119AB93D427D704F616326
sha3_384: 3207b50a067ee1cdcec911e3a328bc1907b20fe75af516a5b83244f37c2535c61c8f1b00a2c13600c5adfa9e47bec44a
ep_bytes: b8d729bf5d030d75200100b8cd66ae3f
timestamp: 2006-12-28 03:56:08

Version Info:

0: [No Data]

Backdoor:Win32/Oderoor!A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Obfuscated.4!c
MicroWorld-eScanTrojan.Obfus.3.Gen
SkyhighBehavesLike.Win32.Generic.cc
MalwarebytesMalware.Heuristic.2090
ZillyaTrojan.Obfuscated.Win32.54281
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005686651 )
K7GWTrojan ( 005686651 )
Cybereasonmalicious.34f108
VirITTrojan.Win32.OBFUSKATED
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Obfuscated.GY
APEXMalicious
AlibabaBackdoor:Win32/Obfuscated.9d3cdad0
NANO-AntivirusTrojan.Win32.Crypt.faywr
TencentWin32.Trojan.Obfuscated.Zylw
EmsisoftTrojan.Obfus.3.Gen (B)
F-SecureTrojan.TR/Crypt.Morphine.Gen
DrWebTrojan.Spambot
VIPRETrojan.Obfus.3.Gen
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminPack.Obfu.Gen
GoogleDetected
AviraTR/Crypt.Morphine.Gen
Antiy-AVLTrojan/Win32.Obfuscated
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Agent.~N7@1np7rc
ArcabitTrojan.Obfus.3.Gen
ViRobotTrojan.Win32.Obfuscated.9252
ZoneAlarmTrojan.Win32.Obfuscated.gy
MicrosoftBackdoor:Win32/Oderoor.gen!A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Obfuscated.R10043
McAfeeSpam-Mailbot.bb.gen
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32BScope.TrojanDropper.Spambot
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:jV2o4/UJn5f3cSjFYAKkRw)
YandexTrojan.GenAsa!2feoeZA2TYY
IkarusTrojan.Win32.Obfuscated
MaxSecureTrojan.Malware.34319.susgen
FortinetW32/Obfuscated.GY!tr
BitDefenderThetaAI:Packer.DCB7D1321E
PandaMalicious Packer
alibabacloudTrojan:Win/Obfuscated.GY

How to remove Backdoor:Win32/Oderoor!A?

Backdoor:Win32/Oderoor!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment