Backdoor

Backdoor.Win32.PcClient.fzgr removal tips

Malware Removal

The Backdoor.Win32.PcClient.fzgr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.PcClient.fzgr virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Win32.PcClient.fzgr?


File Info:

name: E987600EB2F01D34817E.mlw
path: /opt/CAPEv2/storage/binaries/9a4eecd2da9d383fe582d39ed702f03a75c22a7670f761e5670672633dcee062
crc32: AB309106
md5: e987600eb2f01d34817e92ae60a778c3
sha1: d80f340087b4247e75e75d079822f3b0b5343150
sha256: 9a4eecd2da9d383fe582d39ed702f03a75c22a7670f761e5670672633dcee062
sha512: e6e828f5c6742e9138a3a878702f7bf22232b15e5c80540fda0d31410e12bdac1f1da418a5b05df6d2013764e880acba7c19f1d78b9213d62cde9b7025aee802
ssdeep: 768:3aR3182Zln6lItYFQT1bUS4B0/IM/nQjpxwxRmb:3aH82Dn0LFQT1bU/BAD/n2yxsb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B1E2D127FF549E9AC153DA30A311BE392B6FAA7CBD8BD366087313776B4B3451504901
sha3_384: b9e94d37d0fa7b39d53371d5952d02df5923cf35bfe7959b0f962fd0151e09c2232a33a76ffd2cbb4952efa807e0fbec
ep_bytes: 60be000041008dbe0010ffff57eb0b90
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Backdoor.Win32.PcClient.fzgr also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
ClamAVWin.Malware.Microfake-6803907-0
CAT-QuickHealTrojan.Nitol.A8
SkyhighBehavesLike.Win32.Generic.nh
VIPREGen:Heur.Mint.Zard.30
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051b1671 )
BitDefenderGen:Heur.Mint.Zard.30
K7GWTrojan ( 0051b1671 )
Cybereasonmalicious.087b42
ArcabitTrojan.Mint.Zard.30
BaiduWin32.Trojan.ServStart.ax
SymantecDownloader
ESET-NOD32a variant of Win32/ServStart.DT
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.PcClient.fzgr
NANO-AntivirusTrojan.Win32.Staser.cvtxts
SUPERAntiSpywareTrojan.Agent/Gen-ServStart
MicroWorld-eScanGen:Heur.Mint.Zard.30
TencentTrojan.Win32.FakeLpk.aad
SophosTroj/Nitol-R
F-SecureTrojan.TR/ATRAPS.hrva.12
DrWebDDoS.Rincux.495
ZillyaTrojan.Staser.Win32.515
TrendMicroWORM_NITOL.SMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e987600eb2f01d34
EmsisoftGen:Heur.Mint.Zard.30 (B)
IkarusTrojan.Win32.ServStart
JiangminTrojan.Generic.bumtm
GoogleDetected
AviraTR/ATRAPS.hrva.12
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.MicroFake
XcitiumTrojWare.Win32.Scar.GLHP@4pqh94
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmBackdoor.Win32.PcClient.fzgr
GDataWin32.Trojan.Microfake.A
VaristW32/QQhelper.C.gen!Eldorado
AhnLab-V3Trojan/Win32.ServStart.R99364
McAfeeDoS-FBL!4597CCD316CC
TACHYONTrojan/W32.Staser.39936.C
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Zegost
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallWORM_NITOL.SMB
RisingTrojan.Nitol!1.6537 (C64:YzY0OpiHPWXssTZe)
YandexTrojan.GenAsa!nnlnCH+MQ6o
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ServStart.DT!tr
BitDefenderThetaAI:Packer.EB920A301E
AVGWin32:Dh-A [Heur]
AvastWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.PcClient.fzgr?

Backdoor.Win32.PcClient.fzgr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment