Backdoor

Backdoor.Konus (file analysis)

Malware Removal

The Backdoor.Konus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Konus virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Konus?


File Info:

crc32: 1D5B1462
md5: 5d28663b832470f10d5fea13e7761c60
name: 5D28663B832470F10D5FEA13E7761C60.mlw
sha1: 7a8c1c6e0a82f17014060d59d3717b03bc9c444c
sha256: a7294e174451a40548bfb8781e0e614c4a0565c0d5a08ecbb8042eff5607b42d
sha512: 92b338ac83fe8744fced40215a932c4df1658af9ded54415d4c1f626333d2f7b2f6b22ccb6a6a56fe3bd4298b5a2fdb92a0b318ac27d6f99ab6d1c4e9347682f
ssdeep: 6144:qF/e84mFpQxRQo7bR44Mjh5dCfirdt4ARkT+NqmeJePhBHlocqwU/6gtOVd7b/E:qddFpQxqk446dX4DOPeJejh9Nga/EZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Konus also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 005068aa1 )
Elasticmalicious (high confidence)
DrWebTrojan.Kronos.26
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.615501
MalwarebytesBackdoor.Agent
ZillyaTrojan.Kryptik.Win32.2822487
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWSpyware ( 005068aa1 )
Cybereasonmalicious.b83247
CyrenW32/Razy.FU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GTEJ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Razy-9838543-0
KasperskyVHO:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Razy.615501
NANO-AntivirusTrojan.Win32.Kronos.ihrvru
ViRobotTrojan.Win32.Agent.336896.J
MicroWorld-eScanGen:Variant.Razy.615501
TencentWin32.Trojan.Generic.Swlc
Ad-AwareGen:Variant.Razy.615501
SophosMal/Generic-S (PUA)
BitDefenderThetaAI:Packer.25F130571F
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.KRONOSBOT.USMANE421
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.5d28663b832470f1
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Konus.cf
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
GridinsoftTrojan.Win32.Agent.oa!s1
AegisLabTrojan.Win32.Agent.4!c
GDataGen:Variant.Razy.615501
AhnLab-V3Malware/Win32.Generic.C4304831
Acronissuspicious
McAfeeGenericRXAA-AA!5D28663B8324
MAXmalware (ai score=82)
VBA32Backdoor.Konus
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.KRONOSBOT.USMANE421
RisingBackdoor.Konus!8.AC8 (CLOUD)
YandexTrojan.GenAsa!yFmYXAUE2PI
IkarusTrojan.Win32.Crypt
FortinetW32/Kronosbot.C!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor.Konus?

Backdoor.Konus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment