Malware

Win32/Lecna.AF information

Malware Removal

The Win32/Lecna.AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Lecna.AF virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
www.gordeneyes.com
www.kabadefender.com
automation.whatismyip.com
a.tomx.xyz
www.newpresses.com
www.km153.com
www.appsecnic.com

How to determine Win32/Lecna.AF?


File Info:

crc32: 6E96541C
md5: 101bda268bf8277d84b79fe52e25fee4
name: chrome.exe
sha1: 248e2c6821d14c77d497858846bd490a76af4bb3
sha256: b16e1f2adb6e83e787ac7dbed2f09f1fd09f0ac08bf63484056746ebff4dda8b
sha512: cc8678c59ecbeede3eb5702d6a28510441079053c1d9fdbdf82bb3220bda997811742aa8a75d43df318cb6cd44037b6b0f330ca212b819b05500d8d572def455
ssdeep: 1536:z6wtMLOsAYI//hLdjISD6icukSRHvMmizpmOyJCjsiXUoPbf:vMGn/cS9BVvMmmRJjsiXUo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Lecna.AF also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33596199
FireEyeGeneric.mg.101bda268bf8277d
ALYacTrojan.GenericKD.33596199
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00457dfa1 )
BitDefenderTrojan.GenericKD.33596199
K7GWTrojan ( 00457dfa1 )
Cybereasonmalicious.821d14
TrendMicroBKDR_LECNA.SM
BitDefenderThetaGen:NN.ZexaF.34104.fqW@aeBSDflb
SymantecW32.Lecna.E
TrendMicro-HouseCallBKDR_LECNA.SM
Paloaltogeneric.ml
ClamAVWin.Trojan.Backspace-1
GDataTrojan.GenericKD.33596199
KasperskyHEUR:Trojan-Downloader.Win32.Generic
AlibabaTrojanDownloader:Win32/Lecna.fb7da39a
AegisLabTrojan.Win32.Generic.a!c
AvastWin32:Trojan-gen
RisingDownloader.Generic!8.141 (CLOUD)
Ad-AwareTrojan.GenericKD.33596199
SophosTroj/Lecna-V
ComodoMalware@#2ub2g2dvdxtll
F-SecureHeuristic.HEUR/AGEN.1035171
DrWebBackDoor.Dizhi.119
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VBObfus.mm
EmsisoftTrojan.GenericKD.33596199 (B)
APEXMalicious
AviraHEUR/AGEN.1035171
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Dynamer
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D200A327
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
MicrosoftTrojan:Win32/Dynamer!rfn
SentinelOneDFI – Malicious PE
McAfeeRDN/BackDoor-CSB
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesTrojan.Downloader
ESET-NOD32a variant of Win32/Lecna.AF
TencentWin32.Trojan-downloader.Generic.Dtix
IkarusTrojan-Proxy.Win32.Ranky
eGambitUnsafe.AI_Score_98%
FortinetW32/Lecna.AF!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/Lecna.AF?

Win32/Lecna.AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment