Backdoor

About “PcClient.Backdoor.RAT.DDS” infection

Malware Removal

The PcClient.Backdoor.RAT.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PcClient.Backdoor.RAT.DDS virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PcClient.Backdoor.RAT.DDS?


File Info:

name: 80E3789951C97864E869.mlw
path: /opt/CAPEv2/storage/binaries/6b42a58efc78b48045325ef2bef9c21a294dec20e3902fbdca4e3ca54d5acc56
crc32: 3E266F7D
md5: 80e3789951c97864e869d1728119c852
sha1: f0b65ebfe12bf3dbae78858faa2b953312d3fe2e
sha256: 6b42a58efc78b48045325ef2bef9c21a294dec20e3902fbdca4e3ca54d5acc56
sha512: 21e415de64ce3a3d1e55a005e858cfe88efe3e3dfef686db4f259165e87a75e826bcd456d958690f5873ad110d1550bb5b89eed3c99e0051d907e3ef6fffaac6
ssdeep: 192:u53FgVzCfs32dA70zb08vVi1dgkiPDNbZ7lkoynSvhzqB:u53Uz6s3R70zYgkiPp1+0vhzq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12632C70A6795706BCB87847017A9293EE73ABD32792DAC0BE25042513FB3ED5D331263
sha3_384: afd228023d05b2e7fbca62f2cdae82b8736cc7dfeebf7b2bfd10a11f9e4d48c9e40626094732ffd462c36e05b3008ff6
ep_bytes: 60bb0a41400090eb3d9090909090753f
timestamp: 2008-06-14 04:52:17

Version Info:

Comments:
CompanyName: 360安全中心
FileDescription: 360安全卫士签名验证模块
FileVersion: 1, 0, 0, 1004
InternalName: 360Verify
LegalCopyright: Copyright (C) 2006-2008 360.cn
LegalTrademarks:
OriginalFilename: 360Verify.dll
PrivateBuild:
ProductName: 360安全卫士签名验证模块
ProductVersion: 1, 0, 0, 1004
SpecialBuild:
Translation: 0x0804 0x05b0

PcClient.Backdoor.RAT.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PcClient.kYKa
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.425177
FireEyeGeneric.mg.80e3789951c97864
SkyhighBackDoor-CKB.gen.af
McAfeeBackDoor-CKB.gen.af
Cylanceunsafe
ZillyaBackdoor.PcClient.Win32.12134
SangforBackdoor.Win32.Pcclient.Vvjq
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/PcClient.b40b5157
K7GWTrojan ( 004d176f1 )
K7AntiVirusTrojan ( 004d176f1 )
BitDefenderThetaAI:Packer.0E766CEB1F
VirITBackdoor.Win32.PcClient.DTBK
SymantecBackdoor.Pcclient
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PcClient.NFV
TrendMicro-HouseCallBKDR_PCCLIE.SMG
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.425177
AvastWin32:MalOb-U [Cryp]
TencentWin32.Trojan.Patched.Ckjl
EmsisoftGen:Variant.Zusy.425177 (B)
F-SecureTrojan.TR/Patched.Gen
DrWebTrojan.MulDrop.29344
VIPREGen:Variant.Zusy.425177
TrendMicroBKDR_PCCLIE.SMG
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusBackdoor.Win32.PcClient
JiangminBackdoor/PcClient.afne
GoogleDetected
AviraTR/Patched.Gen
VaristW32/PcClient.C.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.PcClient
KingsoftWin32.Trojan.Generic.a
XcitiumBackdoor.Win32.PcClient.~d6@1msrtb
ArcabitTrojan.Zusy.D67CD9
ViRobotBackdoor.Win32.PcClient.17164.B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.425177
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.PcClient.R30425
VBA32Trojan.MulDrop
ALYacGen:Variant.Zusy.425177
MAXmalware (ai score=99)
MalwarebytesPcClient.Backdoor.RAT.DDS
PandaGeneric Malware
RisingBackdoor.Win32.PcClient.wuj (CLASSIC)
YandexTrojan.GenAsa!j7HnnpmtQ28
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/BDoor.CKB!tr.bdr
AVGWin32:MalOb-U [Cryp]
Cybereasonmalicious.951c97
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/PcClient.NDC

How to remove PcClient.Backdoor.RAT.DDS?

PcClient.Backdoor.RAT.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment