Backdoor

Backdoor:Win32/Psychwar.A removal tips

Malware Removal

The Backdoor:Win32/Psychwar.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Psychwar.A virus can do?

  • Authenticode signature is invalid

How to determine Backdoor:Win32/Psychwar.A?


File Info:

name: C7386EFBAAF8712AFA64.mlw
path: /opt/CAPEv2/storage/binaries/4fbd7246649f1817596fb310ed8f00304dac3fd979ededee0df5a1d1343ffcbf
crc32: 3FD0D5BF
md5: c7386efbaaf8712afa64c8a0e55b8671
sha1: c379aa068dfd3f6f25140cd6921fd0cd1b63f241
sha256: 4fbd7246649f1817596fb310ed8f00304dac3fd979ededee0df5a1d1343ffcbf
sha512: 70dc4fc889b4de5726e5f7db47a69fec118b695579d10f5b76c2f4d4d688520eb233424d5038211544914e620999786bbd012d9823fdd652262e5b29cbac43ff
ssdeep: 768:mrYgFNAepbs1Kx7YB5xrWyxiStljgmDBqbDdDW1+oO:m8hep1YBDIStljgmEbd5o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160038D1B7CF1CA33CA9580B205FB8F196BBF6562024151D79B60DDB97D20BE05E3B246
sha3_384: 5c0b756e68dc6a8da318edb76beba9e5e31218078dae70c819049d147e4ea401a5b4aac21a7a17770cac088c91584240
ep_bytes: 558bec6aff683081400068d442400064
timestamp: 1999-11-12 03:30:02

Version Info:

0: [No Data]

Backdoor:Win32/Psychwar.A also known as:

BkavW32.Common.82A6A461
LionicTrojan.Win32.Psychward.m!c
MicroWorld-eScanGen:Trojan.IRC-Backdoor.cmW@aWYdVme
FireEyeGeneric.mg.c7386efbaaf8712a
SkyhighBehavesLike.Win32.Infected.pm
ALYacGen:Trojan.IRC-Backdoor.cmW@aWYdVme
Cylanceunsafe
ZillyaBackdoor.Psychward.Win32.47
SangforBackdoor.Win32.Psychward.Vdyj
K7AntiVirusTrojan ( 000025741 )
AlibabaBackdoor:Win32/Psychward.430b52dd
K7GWTrojan ( 000025741 )
BitDefenderThetaAI:Packer.C762E3AC1E
VirITBackdoor.Win32.PSYCHWARD
SymantecBackdoor.Psychward
Elasticmalicious (high confidence)
ESET-NOD32Win32/Psychward.A
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Psychward.a
BitDefenderGen:Trojan.IRC-Backdoor.cmW@aWYdVme
NANO-AntivirusTrojan.Win32.Psychward.gmkk
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.115d0e80
TACHYONBackdoor/W32.Psychward.40960
EmsisoftGen:Trojan.IRC-Backdoor.cmW@aWYdVme (B)
F-SecureTrojan.TR/Psychward.Srv-2
DrWebBackDoor.Psychward
VIPREGen:Trojan.IRC-Backdoor.cmW@aWYdVme
TrendMicroTROJ_PSYCHWARD.A
SophosMal/IRCBot-B
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.IRC-Backdoor.cmW@aWYdVme
JiangminBackdoor/Psychward.a
WebrootW32.Trojan.Backdoor-Psychward
GoogleDetected
AviraTR/Psychward.Srv-2
Antiy-AVLTrojan[Backdoor]/Win32.Psychward
KingsoftWin32.Hack.Psychward.a
XcitiumBackdoor.Win32.Psychward.A@3nkr
ArcabitTrojan.IRC-Backdoor.ED7C70
ViRobotBackdoor.Win32.Psychward.40960
ZoneAlarmBackdoor.Win32.Psychward.a
MicrosoftBackdoor:Win32/Psychwar.A
VaristW32/Risk.JOKX-7612
McAfeeArtemis!C7386EFBAAF8
MAXmalware (ai score=100)
VBA32Backdoor.Psychward
MalwarebytesGeneric.Malware/Suspicious
PandaBck/Psychward
TrendMicro-HouseCallTROJ_PSYCHWARD.A
RisingTrojan.Psychward.a (CLASSIC)
YandexBackdoor.Psychward.A
IkarusBackdoor.Win32.IRCBot
MaxSecureTrojan.Malware.1846624.susgen
FortinetW32/Psychward.A!tr.bdr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Psychwar.A?

Backdoor:Win32/Psychwar.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment