Backdoor

Olmarik.Backdoor.Bot.DDS (file analysis)

Malware Removal

The Olmarik.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Olmarik.Backdoor.Bot.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Creates a copy of itself

How to determine Olmarik.Backdoor.Bot.DDS?


File Info:

name: DEA5EA3D357638913D4C.mlw
path: /opt/CAPEv2/storage/binaries/aa0740a68459ff5b1709cc2245ff984617a4c4c7a2ab0687622076e50e6a437d
crc32: AFDF81B9
md5: dea5ea3d357638913d4c369f99be290f
sha1: ee8b36902bd329f049c49f51c1fb33a126aed835
sha256: aa0740a68459ff5b1709cc2245ff984617a4c4c7a2ab0687622076e50e6a437d
sha512: 45b6cd518abf8d2e4ed1819b2a0397279035239b34698fc8afab510899e791617078fe93391837c4ef6db0b7d69ddeeaf019fc035706d52a9a2071731b2784b3
ssdeep: 3072:M6nsvPvApnUbi9UxWDREIipChtTHB8SD8i7/aFi:/snApCCUUR8CPThD8iTv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BC312317365814DC07F96721B7907DD2FB9FCD16E2AC72F991CB09989B4F922862321
sha3_384: a4d4ddb05984ac4ee412d4004c2b56cc35b7ee4e9f1714aea513799196d8c3001c4429dca30dac34384f683b6f3530d0
ep_bytes: 558bec81ec1001000053566a5a33db8d
timestamp: 2010-08-06 05:56:18

Version Info:

0: [No Data]

Olmarik.Backdoor.Bot.DDS also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.KS.6
ClamAVWin.Trojan.Tdss-6988206-0
FireEyeGeneric.mg.dea5ea3d35763891
CAT-QuickHealTrojan.Alureon.DE
ALYacGen:Trojan.Heur.KS.6
MalwarebytesOlmarik.Backdoor.Bot.DDS
VIPREGen:Trojan.Heur.KS.6
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00232b2b1 )
AlibabaTrojan:Win32/Olmarik.10ef900c
K7GWTrojan ( 00232b2b1 )
Cybereasonmalicious.d35763
CyrenW32/TDSS.I.gen!Eldorado
SymantecBackdoor.Tidserv.M
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Olmarik.AQQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.KS.6
NANO-AntivirusTrojan.Win32.TDSS.brdkk
SUPERAntiSpywareRootkit.Agent/Gen-Trexer
AvastWin32:Alureon-WR [Rtk]
TencentWin32.Trojan.Generic.Rimw
TACHYONTrojan/W32.TDSS.129024.E
EmsisoftGen:Trojan.Heur.KS.6 (B)
F-SecureTrojan.TR/Shutdown.aba
DrWebBackDoor.Tdss.based.7
TrendMicroBKDR_TDSS.SMZ
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.KS.6
JiangminPack.TDSS.Gen
WebrootW32.Alureon.Rootkit
AviraTR/Shutdown.aba
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Olmarik.AOG@2x4g4s
ArcabitTrojan.Heur.KS.6
ViRobotTrojan.Win32.TDSS.129024.C
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Alureon.DX
GoogleDetected
AhnLab-V3Trojan/Win32.Tdss.R3562
McAfeeGeneric Dropper.va.gen.w
MAXmalware (ai score=100)
VBA32Trojan.TDSS.7
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_TDSS.SMZ
RisingTrojan.Alureon!8.227 (TFE:5:5iVeCVhM4k)
YandexTrojan.GenAsa!Vsv5q7gakF8
IkarusTrojan-Downloader.Win32.CodecPack
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/TDSS.ADU!tr
BitDefenderThetaAI:Packer.A56603B614
AVGWin32:Alureon-WR [Rtk]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Olmarik.Backdoor.Bot.DDS?

Olmarik.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment