Backdoor

Should I remove “Backdoor.Psychward”?

Malware Removal

The Backdoor.Psychward is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Psychward virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor.Psychward?


File Info:

name: 963A21FD40BC9F7467EC.mlw
path: /opt/CAPEv2/storage/binaries/a953d2ee6204a43d79b07d0e5e31b85f1b94b26c7e7f33c4687da0aa0fc5a640
crc32: B5F32A12
md5: 963a21fd40bc9f7467ecfd7efeb80b04
sha1: fa2a16214cc9fede58feb1f18e94fb40b9cd0b3f
sha256: a953d2ee6204a43d79b07d0e5e31b85f1b94b26c7e7f33c4687da0aa0fc5a640
sha512: 1e9847e87ab75554dc16efbbc25f66c430bbab041c8ac550f49ee0070b0f3fb2d01dbaa413e10060fd938a96aaaa2f9214558f7db4f57d0f2d67a3d3c309df45
ssdeep: 3072:Vs1EexhLdnU7XLxYsoQ4KMmQXnTTTvlhZht9Ninho+0/fkyEPVY4mXMAikL8hn:WiexgXLWK4PmO/Hn5XLEz6Mbk4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1713412C2C1D80923F52D10B83EA6A56D7ADABEA13D4C0FF3274DD6DA39756327E10468
sha3_384: 9c4f800015457202178ac5be32eb3c0055af76bb345853ea350d411d7927743c2d0e52a797dbe3f248e4fa501851fea1
ep_bytes: e9a60000001a1c5d0044005d0048005d
timestamp: 1999-05-18 16:38:04

Version Info:

Translation: 0x0404 0x04b0
CompanyName: 克洛奇工作坊
LegalCopyright: Copyright 1999-2009 Croach Chang
LegalTrademarks: -= Croach =-
ProductName: 皮卡丘方塊
FileVersion: 2.00
ProductVersion: 2.00
InternalName: Picachu
OriginalFilename: Picachu.exe

Backdoor.Psychward also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.963a21fd40bc9f74
SkyhighBehavesLike.Win32.VirRansom.dc
McAfeeGenericRXEN-YG!963A21FD40BC
Cylanceunsafe
VIPREGen:Trojan.Heur.VP2.oy1@aqsQGShj
CrowdStrikewin/malicious_confidence_90% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
VirITTrojan.Win32.Generic.DJD
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.VP2.oy1@aqsQGShj
NANO-AntivirusTrojan.Win32.Kolabc.crkzqb
MicroWorld-eScanGen:Trojan.Heur.VP2.oy1@aqsQGShj
EmsisoftGen:Trojan.Heur.VP2.oy1@aqsQGShj (B)
ZillyaWorm.Kolabc.Win32.2428
Trapminemalicious.moderate.ml.score
IkarusBackdoor.Win32.Psychward
GDataGen:Trojan.Heur.VP2.oy1@aqsQGShj
JiangminWorm/Kolabc.blo
VaristW32/A-9bd2ab42!Eldorado
Kingsoftmalware.kb.a.921
ArcabitTrojan.Heur.VP2.EC760A
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
MicrosoftPWS:Win32/Zbot!ml
GoogleDetected
AhnLab-V3Worm/Win32.Kolabc.R64021
VBA32Backdoor.Psychward
ALYacGen:Trojan.Heur.VP2.oy1@aqsQGShj
MAXmalware (ai score=84)
MalwarebytesTrojan.Agent
ZonerProbably Heur.ExeHeaderP
TrendMicro-HouseCallHV_ZYX_BH012B0B.TOMC
SentinelOneStatic AI – Suspicious PE
BitDefenderThetaAI:Packer.1C43E9FD20
Cybereasonmalicious.14cc9f
DeepInstinctMALICIOUS

How to remove Backdoor.Psychward?

Backdoor.Psychward removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment