Backdoor

Backdoor:Win32/Lecna.H!dha removal instruction

Malware Removal

The Backdoor:Win32/Lecna.H!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Lecna.H!dha virus can do?

  • Authenticode signature is invalid

How to determine Backdoor:Win32/Lecna.H!dha?


File Info:

name: 6801AFE50DC75B8DB4B2.mlw
path: /opt/CAPEv2/storage/binaries/7b4a559228c5349809aa6d4e40c5803e32075576c8cf667431932d3632fa6c9b
crc32: 2879CBD6
md5: 6801afe50dc75b8db4b2e6c6f322a575
sha1: 769aa0ec11b60a14625d879df1d59e50b291193d
sha256: 7b4a559228c5349809aa6d4e40c5803e32075576c8cf667431932d3632fa6c9b
sha512: 076c24a5d85de0f8ba79ad266f9f911cdedc54f779a2b87ea3df938e77f50cd1a0c95a5c4b069cef5d7e9cccb213e8e81a8342586fb6d1695625077570459954
ssdeep: 3072:9NB1ge5pUePB5aKrR+DVsRfnRZzFPk2I111KYTI1Uk1ys:51jpUePB5aKrR+D2FPHMzTy1R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FD39E86B583E45AD86E0D30C510D4E18F7BB876ADD5588BF7D0B60EBDE2212B41372B
sha3_384: 1650d8bffa4ea0f08d2ab7ea25ea3060518af03ec8cb8513a9fcd65c82925cca31c5d267fb3ff79d75e1596fab56e393
ep_bytes: 8bec609ce99b4000000068707f400064
timestamp: 2013-04-22 19:59:47

Version Info:

Comments: Opera Internet Browser
CompanyName: Opera Software
FileDescription: Opera Internet Browser
FileVersion: 1055 (1)
InternalName: Opera
LegalCopyright: Copyright Opera Software 1995-
LegalTrademarks:
OriginalFilename: Opera.exe
PrivateBuild:
ProductName: Opera Internet Browser
ProductVersion: 11.00
SpecialBuild:
Translation: 0x0409 0x04b0

Backdoor:Win32/Lecna.H!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Exnet.4!c
DrWebTrojan.DownLoader7.62432
MicroWorld-eScanGeneric.ShellCode.Marte.J.274CA82D
FireEyeGeneric.mg.6801afe50dc75b8d
CAT-QuickHealBackdoor.Lecna.18662
ALYacGeneric.ShellCode.Marte.J.274CA82D
Cylanceunsafe
ZillyaTrojan.Lecna.Win32.95
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059b8b41 )
AlibabaBackdoor:Win32/Lecna.d477fb82
K7GWTrojan ( 0059b8b41 )
Cybereasonmalicious.50dc75
BitDefenderThetaGen:NN.ZexaF.36348.iq0@aeLrCMli
CyrenW32/Lecna.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Lecna.AF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.ShellCode.Marte.J.274CA82D
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:MalOb-FE [Cryp]
TencentMalware.Win32.Gencirc.10bde893
EmsisoftGeneric.ShellCode.Marte.J.274CA82D (B)
F-SecureTrojan.TR/Patched.Gen
VIPREGeneric.ShellCode.Marte.J.274CA82D
TrendMicroTrojanSpy.Win32.EMOTET.SMQB.hp
McAfee-GW-EditionBehavesLike.Win32.Sality.ch
Trapminesuspicious.low.ml.score
SophosMal/PePatch-Y
IkarusTrojan.Win32.Winnti
GDataGeneric.ShellCode.Marte.J.274CA82D
JiangminTrojan.GenericML.yh
AviraTR/Patched.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Win32.Unknown
ArcabitGeneric.ShellCode.Marte.J.274CA82D
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Lecna.H!dha
GoogleDetected
AhnLab-V3Win-Trojan/Downloader.57344.AAQ
McAfeeGenericRXUS-CH!6801AFE50DC7
VBA32Trojan.Downloader
MalwarebytesMalware.AI.2893048996
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMQB.hp
RisingBackdoor.Hupigon!8.B57 (TFE:3:9ZR3ES2hAvB)
YandexTrojan.Lecna!zrhOwmPHJrQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.185628869.susgen
FortinetW32/GenKryptik.GCTV!tr
AVGWin32:MalOb-FE [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Lecna.H!dha?

Backdoor:Win32/Lecna.H!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment