Backdoor

Backdoor:Win32/RDR removal guide

Malware Removal

The Backdoor:Win32/RDR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/RDR virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Backdoor:Win32/RDR?


File Info:

name: 9F7D2AE7ABEA2B782171.mlw
path: /opt/CAPEv2/storage/binaries/f2bc10cb32cf17de0b482b5f2d6b81d031bd420bf985bba7b2da1859f1d4d126
crc32: F9FBBD0E
md5: 9f7d2ae7abea2b782171e157c51d533c
sha1: e7ea4dd8c23d4730994d8cf0cd5184a3727833c2
sha256: f2bc10cb32cf17de0b482b5f2d6b81d031bd420bf985bba7b2da1859f1d4d126
sha512: 88970d88ec6670843f5c5f53f309255da044ffbd460f12cb4f22ea940761f953ce33d0001eb3d157ae0d69411b7d6a2d9a445499330cf69a9a7530876a683d09
ssdeep: 3072:ZXPz/Lf/HTnLfj3bvznQ2cYjjSuY7naqsGc4MTdimv5x30e5kSRM:9cYjjWc4MxFSmkL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AF3F7732AD76CA0ED2546F204E653F1987CB56A1A87B9DDFF109D32893F423A632047
sha3_384: 5788519ac9dc394e4197a8abc9a09befa7f4bc55e3cee6883edcdcc525b9c1d2d557ab105db5e3452d4ab18d887b8af8
ep_bytes: 558bec6aff6840e24100685084410064
timestamp: 2001-03-16 23:24:03

Version Info:

0: [No Data]

Backdoor:Win32/RDR also known as:

BkavW32.AIDetectMalware
DrWebBackDoor.Rdr
MicroWorld-eScanGen:Heur.Mint.SP.Sneaky.1
ClamAVWin.Trojan.Agent-1011009
FireEyeGeneric.mg.9f7d2ae7abea2b78
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXSO-GX!9F7D2AE7ABEA
MalwarebytesGeneric.Malware/Suspicious
ZillyaBackdoor.RDR.Win32.1
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005115d31 )
K7GWTrojan ( 005115d31 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.190C1ACC1E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/RDR
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.RDR
BitDefenderGen:Heur.Mint.SP.Sneaky.1
NANO-AntivirusTrojan.Win32.RDR.fxeo
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Rdr.Kcnw
EmsisoftGen:Heur.Mint.SP.Sneaky.1 (B)
F-SecureTrojan.TR/Spy.Gen
VIPREGen:Heur.Mint.SP.Sneaky.1
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.SP.Sneaky.1
JiangminBackdoor/RDR
GoogleDetected
AviraTR/Spy.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Backdoor]/Win32.RDR
Kingsoftmalware.kb.a.1000
XcitiumBackdoor.Win32.RDR@1cu1
ArcabitTrojan.Mint.SP.Sneaky.1
ViRobotBackdoor.Win32.A.RDR.56320
ZoneAlarmBackdoor.Win32.RDR
MicrosoftBackdoor:Win32/RDR
AhnLab-V3Trojan/Win32.Genome.R129690
VBA32BScope.Worm.Leave
Cylanceunsafe
PandaBackdoor Program.LC
RisingTrojan.RDR (CLASSIC)
YandexTrojan.GenAsa!TG75Xj2LyBM
AVGWin32:Trojan-gen
Cybereasonmalicious.8c23d4
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/RDR?

Backdoor:Win32/RDR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment