Backdoor

Orcus.Backdoor.RAT.DDS removal instruction

Malware Removal

The Orcus.Backdoor.RAT.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Orcus.Backdoor.RAT.DDS virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Orcus.Backdoor.RAT.DDS?


File Info:

name: A2A5A8BFB8E762291E4D.mlw
path: /opt/CAPEv2/storage/binaries/eb3141858805af0c0e4a41a6365d9767118e9679b26d4c35bad50f21ecf410f1
crc32: 6F430C41
md5: a2a5a8bfb8e762291e4d1dd28a793b21
sha1: b816d4bdffa688ecf191092c6575ce4d40573f30
sha256: eb3141858805af0c0e4a41a6365d9767118e9679b26d4c35bad50f21ecf410f1
sha512: 32edfcbefc80ee50cc7f6e7d7ba178d64f2e1e22abb7bb7c91b9e84cf4fe4358e69b5b9cd1383fcf11d792844d5df31738a0721d3045b25da392c3f40283ff9f
ssdeep: 49152:gx7yl7yDgg7yl7yDgR7yl7yDgx7yl7yDgS7yl7yDgR7yl7yDgx7yl7yDga:gxmlmDggmlmDgRmlmDgxmlmDgSmlmDgu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15CE5B816F760941AF54280B53969E2BBB95A2D721681DC03FB826F5838B47D3F4F4B0B
sha3_384: 2d5e151d023b8bb3dd3c0fd3b13138829a57611b513db77a6e7a4435a0cc7ff44b1f0b6ad7644ec956e44c78c4510392
ep_bytes: 687c224000e8f0ffffff000000000000
timestamp: 2008-11-16 03:29:47

Version Info:

0: [No Data]

Orcus.Backdoor.RAT.DDS also known as:

BkavW32.AIDetect.malware1
AVGWin32:DropperX-gen [Drp]
MicroWorld-eScanTrojan.GenericKD.50234818
FireEyeGeneric.mg.a2a5a8bfb8e76229
CAT-QuickHealTrojan.LunamVMF.S26739973
ALYacTrojan.GenericKD.50234818
CylanceUnsafe
VIPRETrojan.GenericKD.50234818
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0054dc901 )
K7GWTrojan ( 00590fc41 )
Cybereasonmalicious.fb8e76
BaiduWin32.Trojan.Otfrem.b
VirITTrojan.Win32.VBCrypt.ELK
CyrenW32/Barys.AU.gen!Eldorado
SymantecW32.SillyFDC.BCR
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Otfrem.C
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Otfrem-9939925-0
KasperskyTrojan.Win32.Lunam.a
BitDefenderTrojan.GenericKD.50234818
NANO-AntivirusTrojan.Win32.Lunam.jnmpjo
AvastWin32:DropperX-gen [Drp]
TencentTrojan.Win32.Lunam.ta
Ad-AwareTrojan.GenericKD.50234818
EmsisoftTrojan.GenericKD.50234818 (B)
ComodoTrojWare.Win32.Spy.Agent.1396070@1qn3u3
DrWebWin32.HLLW.Autoruner.48319
TrendMicroTROJ_GEN.R03BC0OKK22
McAfee-GW-EditionBehavesLike.Win32.Generic.vm
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/SillyFDC-K
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.50234818
JiangminTrojan/Lunam.b
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Lunam.a
ArcabitTrojan.Generic.D2FE85C2
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
McAfeeGeneric VB.b
VBA32Trojan.Otfrem
MalwarebytesOrcus.Backdoor.RAT.DDS
TrendMicro-HouseCallTROJ_GEN.R03BC0OKK22
RisingWorm.Win32.VBCode.ep (CLASSIC)
IkarusVirus.Win32.Otfrem
MaxSecureTrojan.W32.Lunam.A
FortinetW32/Lunam.A!tr
BitDefenderThetaGen:NN.ZevbaF.34796.4oZ@aq1xs8f
PandaTrj/CI.A

How to remove Orcus.Backdoor.RAT.DDS?

Orcus.Backdoor.RAT.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment