Backdoor

Backdoor:Win32/Kanav.A (file analysis)

Malware Removal

The Backdoor:Win32/Kanav.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Kanav.A virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Kanav.A?


File Info:

name: 4B246D09E60C4EC49B87.mlw
path: /opt/CAPEv2/storage/binaries/660cf77581e8a94bbf54c8154c154c007a5f3e6f3feb816591d7c7e0b88841de
crc32: 3CEFEB75
md5: 4b246d09e60c4ec49b87f88bc97e1e1c
sha1: 4eb73fdb020e701192fe287ff4d976d1dfbae74d
sha256: 660cf77581e8a94bbf54c8154c154c007a5f3e6f3feb816591d7c7e0b88841de
sha512: abf829596776fdf9764b1e7099f478a29685fc22c24bb119aa192160a4f2ee528fee0874aa743c1b107b2e5a62c4dc7d21d75f7634da845a66b648d5f6a49b04
ssdeep: 768:w37zj55N7fnokbb/RjUtS0xWboBK4hlwYB:wj55NzBv/1oc4hl9B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109235B3B75C48476C582417105E48F6B9FBF2F31129211A367E0AD466E72ADAE22F20E
sha3_384: 113e43471c0315016cc17867bb57d8aa12fb6d9d614aa95e6dafe41e0b4e2dda4b631227113121ff335d2906db946d8f
ep_bytes: 558bec6aff680071400068103f400064
timestamp: 2011-12-16 15:36:39

Version Info:

0: [No Data]

Backdoor:Win32/Kanav.A also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.326892
ClamAVWin.Trojan.Agent-364682
CAT-QuickHealBackdoor.Kanav.MUE.AP3
McAfeeDownloader-CRU
Cylanceunsafe
ZillyaDropper.Agent.Win32.93517
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 00321db61 )
K7GWTrojan-Downloader ( 00321db61 )
Cybereasonmalicious.9e60c4
BitDefenderThetaGen:NN.ZexaF.36196.cmX@aeelGUk
CyrenW32/Sadenav.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.RAK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Agent.gfbs
BitDefenderGen:Variant.Zusy.326892
NANO-AntivirusTrojan.Win32.Agent.dayvyd
SUPERAntiSpywareTrojan.Agent/Gen-Kanav
AvastWin32:Inject-AQV [Trj]
TencentTrojan-Dropper.Win32.Agent.kb
TACHYONTrojan/W32.Agent.47108.I
EmsisoftGen:Variant.Zusy.326892 (B)
BaiduWin32.Trojan-Downloader.Agent.bl
F-SecureTrojan.TR/Dldr.Agent.udwaf
DrWebTrojan.Inject.59293
VIPREGen:Variant.Zusy.326892
McAfee-GW-EditionBehavesLike.Win32.Downloader.pt
FireEyeGeneric.mg.4b246d09e60c4ec4
SophosTroj/Kanav-A
IkarusTrojan.Win32.Alyak
GDataWin32.Trojan.PSE.1KYMKY
JiangminTrojanDropper.Agent.bfzc
WebrootW32.Trojan.Gen
AviraTR/Dldr.Agent.udwaf
Antiy-AVLTrojan[Dropper]/Win32.Agent
XcitiumTrojWare.Win32.TrojanDownloader.Small.REK@4n2or7
ArcabitTrojan.Zusy.D4FCEC
ViRobotTrojan.Win32.Downloader.45094
ZoneAlarmTrojan-Dropper.Win32.Agent.gfbs
MicrosoftBackdoor:Win32/Kanav.A
GoogleDetected
AhnLab-V3Dropper/Win32.OnlineGameHack.R18748
VBA32BScope.Trojan.Jorik
ALYacGen:Variant.Zusy.326892
MAXmalware (ai score=89)
MalwarebytesMalware.AI.1765439341
PandaTrj/Genetic.gen
RisingBackdoor.Kanav!1.9D4F (CLASSIC)
YandexTrojan.GenAsa!T94nMOBORCA
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.TODU!tr
AVGWin32:Inject-AQV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Kanav.A?

Backdoor:Win32/Kanav.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment