Backdoor

How to remove “Backdoor:Win32/Ecltys.A”?

Malware Removal

The Backdoor:Win32/Ecltys.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Ecltys.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Ecltys.A?


File Info:

name: 9F31B1BA424146AAB6F5.mlw
path: /opt/CAPEv2/storage/binaries/eda4dbc239f83c1d0c6dd781c106be1cea4c931ac687358437f78b900c22eef8
crc32: BFC5EE38
md5: 9f31b1ba424146aab6f54dd0d239d82f
sha1: 87c90da2d3517091078e0a2385f87aa795baa34e
sha256: eda4dbc239f83c1d0c6dd781c106be1cea4c931ac687358437f78b900c22eef8
sha512: 331ee5238e5eebda259fb26a7ba0de5438b1017baab0080da3ed39f4c34607ba6137e2562fea67d5a2702ef37b00f26b2b32ae369cc8c7c7964a898bad2ad88e
ssdeep: 3072:ei4Vc398rKcVMpe59k2/7s+zK8Rf/xVxxcc57uVaUbEd:gVc3GKc9akzD5V0muw/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184048C21FA81C0B3C41B247104B9DB76AE7DB662176846C3B7941F7DAE113E19F3A24E
sha3_384: 0d58cba5d6a97907ed463a4196cff9124363bdbea6f816d3c504916b2e2cca540e006a2a2e3acea6ed6938afd97bd75d
ep_bytes: e85d780000e9a4feffffcccccccc8b4c
timestamp: 2012-02-08 00:42:00

Version Info:

0: [No Data]

Backdoor:Win32/Ecltys.A also known as:

DrWebBackDoor.Siggen.45477
MicroWorld-eScanGen:Variant.Midie.77142
FireEyeGeneric.mg.9f31b1ba424146aa
ALYacGen:Variant.Midie.77142
CylanceUnsafe
VIPREGen:Variant.Midie.77142
BitDefenderGen:Variant.Midie.77142
Cybereasonmalicious.a42414
SymantecTrojan.Ecltys!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.PME
ClamAVWin.Malware.Ecltys-9802768-0
KasperskyBackdoor.Win32.Agent.dbcl
NANO-AntivirusTrojan.Win32.Ecltys.fekwvi
Ad-AwareGen:Variant.Midie.77142
ZillyaBackdoor.Agent.Win32.44066
McAfee-GW-EditionBackDoor-FAFS
EmsisoftGen:Variant.Midie.77142 (B)
IkarusBackdoor.Win32.Ecltys
JiangminBackdoor/Agent.cwkd
Antiy-AVLTrojan/Generic.ASMalwS.61
MicrosoftBackdoor:Win32/Ecltys.A
GDataGen:Variant.Midie.77142
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ecltys.C253331
McAfeeBackDoor-FAFS
MAXmalware (ai score=84)
VBA32Backdoor.Agent
MalwarebytesMalware.AI.1499352627
PandaTrj/Zbot.S
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.9DC56!tr
AVGWin32:BackdoorX-gen [Trj]
AvastWin32:BackdoorX-gen [Trj]

How to remove Backdoor:Win32/Ecltys.A?

Backdoor:Win32/Ecltys.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment