Backdoor

Backdoor.Win32.PcClient.cev removal instruction

Malware Removal

The Backdoor.Win32.PcClient.cev is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.PcClient.cev virus can do?

  • Reads data out of its own binary image
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.PcClient.cev?


File Info:

crc32: 603CD7B5
md5: 3a08918c37291c74a1290deb7bbb0692
name: 3A08918C37291C74A1290DEB7BBB0692.mlw
sha1: 99ac15f357826719750bc2ee81f857d022cea9e9
sha256: 1979139bc2bf9a7a5afe2264575ba3b3924cddfe273eabd1b9696afda582dc2e
sha512: 45c824fcb7452cf9bf2f7bce95ddb6cbf1371669f10328c7abd452b0498527930f7b45665e110d4f1acb6ce357c47242bb045c329f17dcb7fc94ac71b1e8a674
ssdeep: 768:hX8hAviDxcTxSXyLfBdPot43tliJd2J1AvKJITdE3EV5FCtAwN9rmS5h58A1bF:6/cpLfBdF+d2J1AvqI/TxwN9rmSD62Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.PcClient.cev also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0000042d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Proxy.20157
CynetMalicious (score: 100)
ALYacTrojan.Crypt.DG
CylanceUnsafe
ZillyaBackdoor.PcClient.Win32.24
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0000042d1 )
Cybereasonmalicious.c37291
CyrenW32/PcClient.C.gen!Eldorado
SymantecBackdoor.Pcclient
ESET-NOD32a variant of Win32/PcClient
APEXMalicious
AvastWin32:PcClient-QV [Trj]
ClamAVWin.Trojan.PcClient-51
KasperskyBackdoor.Win32.PcClient.cev
BitDefenderTrojan.Crypt.DG
NANO-AntivirusTrojan.Win32.PcClient.jpbz
ViRobotBackdoor.Win32.PcClient.56337
SUPERAntiSpywareTrojan.Agent/Gen-PcClient
MicroWorld-eScanTrojan.Crypt.DG
TencentTrojan.Win32.PCClient.tgh
Ad-AwareTrojan.Crypt.DG
SophosML/PE-A + Troj/PcClien-NH
ComodoBackdoor.Win32.PCClient.~R@fn6k
F-SecureBackdoor.BDS/PcClient.brp
BitDefenderThetaAI:Packer.A3F27FD11E
VIPREBackdoor.Win32.Pcclient (v)
TrendMicroBKDR_PCCLIE.SMI
McAfee-GW-EditionBehavesLike.Win32.Backdoor.qc
FireEyeGeneric.mg.3a08918c37291c74
EmsisoftTrojan.Crypt.DG (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/PcClient.cbi
WebrootW32.Backdoor.Gen
AviraBDS/PcClient.brp
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.DCDE
MicrosoftBackdoor:Win32/PcClient.DA
ZoneAlarmBackdoor.Win32.PcClient.cev
GDataTrojan.Crypt.DG
TACHYONBackdoor/W32.PcClient.52959
AhnLab-V3Win-Trojan/PcClient1.Gen
McAfeeBackDoor-CKB.ax
MAXmalware (ai score=86)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.3902706413
PandaBck/PcClient.JK
TrendMicro-HouseCallBKDR_PCCLIE.SMI
RisingBackdoor.Win32.PcClient.ebb (CLASSIC)
YandexTrojan.GenAsa!noOaYtRbtW4
IkarusTrojan.Crypt
FortinetW32/PcClient.BIB!tr
AVGWin32:PcClient-QV [Trj]

How to remove Backdoor.Win32.PcClient.cev?

Backdoor.Win32.PcClient.cev removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment