Backdoor

Backdoor:Win32/Oderoor!D removal

Malware Removal

The Backdoor:Win32/Oderoor!D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Oderoor!D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Oderoor!D?


File Info:

name: 35C04DD6222806CA18DC.mlw
path: /opt/CAPEv2/storage/binaries/ce39767e2054f7ea37dba3a77ba89f78f658cf6ae0edbcb7949760436011952d
crc32: 812F4EB5
md5: 35c04dd6222806ca18dc5ee4ec03982b
sha1: 7204f1979e8b02191d56595009d6ceb25b9ce3bc
sha256: ce39767e2054f7ea37dba3a77ba89f78f658cf6ae0edbcb7949760436011952d
sha512: 1c2510def4f3f7844ae8cdc4801eb0d7c80295b18ff495d2ff3a88ff1e23a3509aba19d788ac789a21c302ed32651b454df51f9869d66b8406848c270859dc90
ssdeep: 3072:v7Om0kN24HKg0YIyqmIluyTHYRaUHBRmIIxypx3pa6mciJQQToawBUHOQnHlAn+u:6m0kNBqgTTqhluysT6Ax3pRlSoaYQOQB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F414128FB284D3B4D4863BB46407C96EB524E7806545B8CCFB76C04E26728E72F7A578
sha3_384: 5a7ba9478c697d71db5ac4bbfbb923cd4a694af6d507be9662a2fd6bc966c981ba6a76b20b9d06a83954c3e1082d7b7c
ep_bytes: 68c843efffe8fa230000000047657443
timestamp: 2007-12-09 06:23:28

Version Info:

0: [No Data]

Backdoor:Win32/Oderoor!D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Pakes.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.35c04dd6222806ca
SkyhighBehavesLike.Win32.Generic.cc
McAfeeArtemis!35C04DD62228
Cylanceunsafe
ZillyaTrojan.Pakes.Win32.18257
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 000720041 )
AlibabaBackdoor:Win32/Pakes.b6bc1516
K7GWTrojan ( 000720041 )
Cybereasonmalicious.622280
BitDefenderThetaAI:Packer.3D31C6A81E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Meslice.A
APEXMalicious
KasperskyTrojan.Win32.Pakes.oip
BitDefenderBackdoor.Oderoor.3.Gen
NANO-AntivirusTrojan.Win32.Pakes.tnkpc
MicroWorld-eScanBackdoor.Oderoor.3.Gen
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Pakes.Ncnw
SophosMal/EncPk-CK
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREBackdoor.Oderoor.3.Gen
Trapminemalicious.moderate.ml.score
EmsisoftBackdoor.Oderoor.3.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Pakes
Kingsoftmalware.kb.b.983
MicrosoftBackdoor:Win32/Oderoor.gen!D
XcitiumMalware@#3r3657onx9n6t
ArcabitBackdoor.Oderoor.3.Gen
ZoneAlarmTrojan.Win32.Pakes.oip
GDataBackdoor.Oderoor.3.Gen
GoogleDetected
ALYacBackdoor.Oderoor.3.Gen
MAXmalware (ai score=100)
PandaGeneric Malware
ZonerProbably Heur.ExeHeaderL
RisingTrojan.Win32.Nodef.fhk (CLASSIC)
YandexTrojan.Pakes!pMpercNHlHI
IkarusBackdoor.Win32.Oderoor
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Meslice.A

How to remove Backdoor:Win32/Oderoor!D?

Backdoor:Win32/Oderoor!D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment