Backdoor

Backdoor:Win32/PcClient.DA removal tips

Malware Removal

The Backdoor:Win32/PcClient.DA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/PcClient.DA virus can do?

  • Reads data out of its own binary image
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/PcClient.DA?


File Info:

crc32: 6EFFBE95
md5: 3a2a38e3bc8bbcd3685f01e008dfdcd0
name: 3A2A38E3BC8BBCD3685F01E008DFDCD0.mlw
sha1: 7f16d0891d880e75e16207ff03131bb7584fdfc4
sha256: 6b3bcfbc21bc2ce59f5b637b39b1b38f075ef650dfde74422e99998b105fb33b
sha512: 25d144b6ad15ad291faa95d13da4b304b057a11e3fd59cc16622bc527f08e7ed302b2d6a2a1f1d18d39134e4cf37d7814216132360b1a2f4e01cb523747f4d45
ssdeep: 1536:6/k1dRCEk0pVScfr1Eo0ilbCFiWPW+Y+vyzTc:ykMEdSXC0iG6PA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/PcClient.DA also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0000042d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Proxy.20157
CynetMalicious (score: 100)
ALYacTrojan.Crypt.DG
CylanceUnsafe
ZillyaBackdoor.PcClient.Win32.24
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0000042d1 )
Cybereasonmalicious.3bc8bb
CyrenW32/PcClient.C.gen!Eldorado
SymantecBackdoor.Pcclient
ESET-NOD32a variant of Win32/PcClient
APEXMalicious
AvastWin32:PcClient-QV [Trj]
ClamAVWin.Trojan.PcClient-51
KasperskyBackdoor.Win32.PcClient.cev
BitDefenderTrojan.Crypt.DG
NANO-AntivirusTrojan.Win32.PcClient.jpbz
ViRobotBackdoor.Win32.PcClient.56337
SUPERAntiSpywareTrojan.Agent/Gen-PcClient
MicroWorld-eScanTrojan.Crypt.DG
TencentTrojan.Win32.PCClient.tgh
Ad-AwareTrojan.Crypt.DG
SophosML/PE-A + Troj/PcClien-NH
ComodoBackdoor.Win32.PCClient.~R@fn6k
BitDefenderThetaAI:Packer.A3F27FD11E
VIPREBackdoor.Win32.Pcclient (v)
TrendMicroBKDR_PCCLIE.SMI
McAfee-GW-EditionBehavesLike.Win32.Backdoor.qc
FireEyeGeneric.mg.3a2a38e3bc8bbcd3
EmsisoftTrojan.Crypt.DG (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/PcClient.cbi
AviraBDS/PcClient.brp
eGambitUnsafe.AI_Score_91%
Antiy-AVLTrojan/Generic.ASMalwS.DCDE
MicrosoftBackdoor:Win32/PcClient.DA
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Crypt.DG
TACHYONBackdoor/W32.PcClient.52959
AhnLab-V3Win-Trojan/PcClient1.Gen
McAfeeBackDoor-CKB.ax
MAXmalware (ai score=85)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.3902706413
PandaBck/PcClient.JK
TrendMicro-HouseCallBKDR_PCCLIE.SMI
RisingBackdoor.Win32.PcClient.ebb (CLASSIC)
YandexTrojan.GenAsa!noOaYtRbtW4
IkarusTrojan.Crypt
FortinetW32/PcClient.BIB!tr
AVGWin32:PcClient-QV [Trj]

How to remove Backdoor:Win32/PcClient.DA?

Backdoor:Win32/PcClient.DA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment