Backdoor

Backdoor:Win32/Lecna!dha information

Malware Removal

The Backdoor:Win32/Lecna!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Lecna!dha virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

www.km-nyc.com
www.flyeagles.com

How to determine Backdoor:Win32/Lecna!dha?


File Info:

crc32: BC5C92C0
md5: 669f87f2ec48dce3a76386eec94d7e3b
name: malware
sha1: 6b82f126555e7644816df5d4e4614677ee0bda5c
sha256: befb88b89c2eb401900a68e9f5b78764203f2b48264fcc3f7121bf04a57fd408
sha512: 953e0835cf32bb000fe0e6d5e9dfb7220c4e9f7ea5a964e0c25f9f8cc80ef4feda0319fce76f1cfa687cc03f49bc978fa7780d15b45c34cf098082f961d7d087
ssdeep: 768:15jQ4nVHQaeO379u4XckKVCsknBN9A4hUnDxDiNZ957ZpK0IUUiM95Zdz:15jQ4nVHQaeO9uwckKuBN9A4UnDxcbF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Microsoft Corporation. All rights reserved.
InternalName: iexplore
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft(R) Windows(R) Operating System
SpecialBuild:
ProductVersion: 6.00.2900.2180
FileDescription: Internet Explorer
OriginalFilename: IEXPLORE.EXE
Translation: 0x0000 0x04b0

Backdoor:Win32/Lecna!dha also known as:

DrWebBackDoor.Dizhi
MicroWorld-eScanBackdoor.Lecna.AB
FireEyeGeneric.mg.669f87f2ec48dce3
CAT-QuickHealTrojanAPT.LecnaCBack.MUE.Z3
Qihoo-360Win32/Backdoor.6a1
McAfeeBackDoor-CSB
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusTrojan ( 00013a571 )
BitDefenderBackdoor.Lecna.AB
K7GWTrojan ( 00013a571 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroBKDR_LECNA.SM
BitDefenderThetaGen:NN.ZexaF.34090.cq0@amFvQYhb
F-ProtW32/Trojan.AAWD
APEXMalicious
AvastWin32:Lecna-I [Trj]
ClamAVWin.Trojan.Backspace-1
GDataBackdoor.Lecna.AB
KasperskyBackdoor.Win32.Lecna.ab
AlibabaBackdoor:Win32/Lecna.12ff430b
NANO-AntivirusTrojan.Win32.Lecna.johs
AegisLabTrojan.Win32.Lecna.m!c
TencentWin32.Backdoor.Lecna.Wpjz
Ad-AwareBackdoor.Lecna.AB
SophosTroj/Lecna-Q
ComodoBackdoor.Win32.Lecna.AB@1qvxpi
F-SecureWorm.WORM/Rbot.Gen
ZillyaBackdoor.Lecna.Win32.177
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Jeefo.pm
Trapminemalicious.high.ml.score
CMCGeneric.Win32.669f87f2ec!CMCRadar
EmsisoftBackdoor.Lecna.AB (B)
IkarusBackdoor.Win32.Lecna
CyrenW32/Lecnac.A.gen!Eldorado
JiangminBackdoor/Lecna.i
AviraWORM/Rbot.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Lecna
Endgamemalicious (high confidence)
ArcabitBackdoor.Lecna.AB
ZoneAlarmBackdoor.Win32.Lecna.ab
MicrosoftBackdoor:Win32/Lecna!dha
AhnLab-V3Downloader/Win32.Small.R15021
Acronissuspicious
VBA32Backdoor.Lecna
ALYacBackdoor.Lecna.AB
TACHYONBackdoor/W32.Lecna.40960.N
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Lecna.W
TrendMicro-HouseCallBKDR_LECNA.SM
RisingBackdoor.Lecna.bm (CLOUD)
YandexBackdoor.Lecna!6o+rCAoBYU8
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetW32/Generic.AC.1FAF5A!tr
AVGWin32:Lecna-I [Trj]
Cybereasonmalicious.2ec48d
Paloaltogeneric.ml
MaxSecureTrojan.Malware.82921.susgen

How to remove Backdoor:Win32/Lecna!dha?

Backdoor:Win32/Lecna!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment