Trojan

What is “Rodecap.Trojan.Downloader.DDS”?

Malware Removal

The Rodecap.Trojan.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rodecap.Trojan.Downloader.DDS virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Rodecap.Trojan.Downloader.DDS?


File Info:

name: 75A9CA5FD54A9DAB06E7.mlw
path: /opt/CAPEv2/storage/binaries/661f97de5779920c9d49148bcf909c39b699ad79caf79df3732ac7e47f68fbbe
crc32: 6B59404E
md5: 75a9ca5fd54a9dab06e7eaa2e755e6a9
sha1: f3c84de26da4d37cea0d5a66b2790acd3ed1bfb1
sha256: 661f97de5779920c9d49148bcf909c39b699ad79caf79df3732ac7e47f68fbbe
sha512: e136a891e180a251eebc4652552d791dbe69777f7624d94461992ab2e904fcf126156e99a53ec293d44987c1105962c40330615d1af7931ff7b3804f510534b4
ssdeep: 6144:ZqCzjMy8lMNdnKIjH+gQyOHcfbdDOsZcZLGMd06IjDp:kCzYy8lMNdnKIjHa8ZDOsZcZLG7Dp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5947C09FA8AF131C1131AB42E2BE71E4576B69617310EC7F7C49D2D8E612D29B3934E
sha3_384: 1d6edd1fc64c723a10e7362bcacda2d9fd4dd95eae44e47dde13ddf6a4613ba84f8c0d892f67f6fc52c9fe8f8181e14e
ep_bytes: e885920000e978feffffcccccccccccc
timestamp: 2012-11-26 15:32:38

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: Extensible Storage Engine Utilities for Microsoft(R) Windows(R)
FileVersion: 6.1.7600.16385
InternalName: esentutl.exe
LegalCopyright: ᄅ Microsoft Corporation. All rights reserved.
LegalTrademarks: ᄅ Microsoft Corporation. All rights reserved.
OriginalFilename: esentutl.exe
PrivateBuild: esentutl.exe
ProductName: Microsoftᆴ Windowsᆴ Operating System
ProductVersion: 6.1.7600.16385
SpecialBuild: 6.1.7600.16385
Translation: 0x0409 0x04b0

Rodecap.Trojan.Downloader.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIu1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Malware.Au0@aie4DTdi
ClamAVWin.Malware.Rodecap-9890056-0
FireEyeGeneric.mg.75a9ca5fd54a9dab
CAT-QuickHealTrojan.Small.gen
McAfeeDownloader-FIK!75A9CA5FD54A
Cylanceunsafe
ZillyaTrojan.Rodecap.Win32.1613
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f0da1 )
AlibabaMalware:Win32/km_2c5e0.None
K7GWTrojan ( 0040f0da1 )
Cybereasonmalicious.fd54a9
BitDefenderThetaGen:NN.ZexaF.36350.Au0@aie4DTdi
VirITTrojan.Win32.DownLoader7.BYVT
CyrenW32/SmallDl.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Rodecap.AZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Malware.Au0@aie4DTdi
NANO-AntivirusTrojan.Win32.Small.btvxkz
AvastWin32:Rodecap-G [Cryp]
TencentMalware.Win32.Gencirc.10b2e51a
EmsisoftGen:Trojan.Malware.Au0@aie4DTdi (B)
F-SecureTrojan.TR/Dldr.Small.87723
DrWebTrojan.DownLoader7.34365
VIPREGen:Trojan.Malware.Au0@aie4DTdi
TrendMicroTROJ_AGENT_056732.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SophosMal/Qbot-P
IkarusVirus.Win32.Cryptor
GDataGen:Trojan.Malware.Au0@aie4DTdi
JiangminTrojan/Generic.apwlc
WebrootW32.Rogue.Gen
AviraTR/Dldr.Small.87723
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Agent.AWR@4ri3wg
ArcabitTrojan.Malware.EF9AE7
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Small.BH
GoogleDetected
AhnLab-V3Trojan/Win32.Small.R46937
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Trojan.Malware.Au0@aie4DTdi
TACHYONTrojan/W32.Agent.435200.FX
MalwarebytesRodecap.Trojan.Downloader.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_056732.TOMB
RisingTrojan.Rodecap!1.AEDF (CLASSIC)
YandexTrojan.GenAsa!BMy+oolf+zU
SentinelOneStatic AI – Suspicious PE
FortinetW32/Rodecap.BA!tr
AVGWin32:Rodecap-G [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Rodecap.Trojan.Downloader.DDS?

Rodecap.Trojan.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment