Backdoor

What is “Backdoor.Crysan”?

Malware Removal

The Backdoor.Crysan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Crysan virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Crysan?


File Info:

crc32: 3385BD0A
md5: 1ad3853d042ad726fefea84b0d2fe181
name: 1AD3853D042AD726FEFEA84B0D2FE181.mlw
sha1: ede9e408d3a629bed4fd6498c5ba0139110c44fe
sha256: 4630139561d13a1b777368972765fb04cf0b237a850bc94d59ba7d2445d32019
sha512: 01bb4beb02bcd391874368644282ac7eab479f0842e4b0339b676ab304b514aae1785d9c6f0e7c6417de588e77e913e094eea598218ad0e5e928fdd9b78d0170
ssdeep: 12288:m8WvAMYGY5RFNBeU7vgTOzAdCeLh/B4wT:m8W4T17vgKzULBB4wT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Crysan also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72551
CAT-QuickHealBackdoor.Crysan
ALYacBackdoor.RAT.Async
MalwarebytesTrojan.Injector
ZillyaBackdoor.Androm.Win32.75910
SangforMalware
K7AntiVirusTrojan ( 005765f11 )
BitDefenderTrojan.GenericKDZ.72551
K7GWTrojan ( 005765f11 )
Cybereasonmalicious.8d3a62
BitDefenderThetaGen:NN.ZexaF.34804.AyZ@a0NaHaji
CyrenW32/Kryptik.CXB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Injector.EOGL
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Crysan.gen
AlibabaBackdoor:Win32/FormBook.157dfae5
ViRobotTrojan.Win32.Z.Agent.432640.JY
TencentMalware.Win32.Gencirc.10ce3202
Ad-AwareTrojan.GenericKDZ.72551
SophosMal/Generic-S
ComodoMalware@#1p9ianm50b7ak
F-SecureHeuristic.HEUR/AGEN.1139979
DrWebBackDoor.SpyBotNET.25
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103AJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.1ad3853d042ad726
EmsisoftTrojan.GenericKDZ.72551 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1C6IZZR
JiangminTrojan.Generic.gscmo
AviraHEUR/AGEN.1139979
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.Generic.D11B67
ZoneAlarmHEUR:Backdoor.Win32.Crysan.gen
MicrosoftTrojan:Win32/FormBook.VAM!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R363575
McAfeeGenericRXNJ-WJ!1AD3853D042A
VBA32Trojan.Wacatac
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103AJ21
RisingDropper.Agent!1.D191 (CLASSIC)
YandexTrojan.Igent.bVbKhn.36
IkarusTrojan.Win32.Crypt
FortinetMalicious_Behavior.SB
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.38e

How to remove Backdoor.Crysan?

Backdoor.Crysan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment