Backdoor

Should I remove “Backdoor.Zyklon”?

Malware Removal

The Backdoor.Zyklon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Zyklon virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:9050
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • A process was set to shut the system down when terminated
  • Installs Tor on the infected machine
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine Backdoor.Zyklon?


File Info:

crc32: 76527EBD
md5: c6fa4987940347af2b09647ab379a8c8
name: C6FA4987940347AF2B09647AB379A8C8.mlw
sha1: 5929da993968b00d53dd382770dbd21eec430c47
sha256: 2a4a3d742d02e677940111b763b3224ec3bb160b772be5cad5424b34441326a3
sha512: 33a97f803c43e9d8a01f62bb87f33a6db57c67b3ad254e658b93a562ebdd4e8ccea1367e8ff3cfd0fc0b89d8150f83c7b93e663a4d7df2f958e68437d2089bd1
ssdeep: 24576:kiVY4mLd78bcL/p8QevR7HUFoubFtv1ct74zHRiPI1nNG:kZ78UWLHVuhxzxiPI1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor.Zyklon also known as:

K7AntiVirusTrojan ( 700000121 )
CAT-QuickHealTrojan.Generic
ALYacGen:Heur.Ransom.REntS.Gen.1
MalwarebytesBackdoor.Zyklon
ZillyaTrojan.Kryptik.Win32.1221612
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 700000121 )
Cybereasonmalicious.794034
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Zyklon.C
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
AlibabaBackdoor:MSIL/Omaneat.b283b914
NANO-AntivirusTrojan.Win32.Kryptik.ererdg
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
ComodoMalware@#3si91n2ct7yql
BitDefenderThetaGen:NN.ZemsilF.34670.rnW@a0QAEDb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103AA19
FireEyeGeneric.mg.c6fa4987940347af
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
JiangminTrojan.Generic.apsut
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Ransom.REntS.Gen.1
AegisLabTrojan.Win32.Generic.4!c
GDataMSIL.Trojan.Zyklon.A
AhnLab-V3Trojan/Win32.Skeeyah.R194230
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=100)
TrendMicro-HouseCallTROJ_FRS.0NA103AA19
TencentWin32.Trojan.Inject.Auto
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.57260!tr
PandaTrj/GdSda.A
Qihoo-360Win32/TrojanSpy.Omaneat.HwMAEpsA

How to remove Backdoor.Zyklon?

Backdoor.Zyklon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment