Backdoor

Backdoor.Win32.Remcos.mxk removal

Malware Removal

The Backdoor.Win32.Remcos.mxk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.mxk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.mxk?


File Info:

crc32: 22DFFC3A
md5: 9f046aa9e46726891c302fd2db9a3190
name: vbc.exe
sha1: b760b61ed7262d10664deb923944e6a4276df77d
sha256: adb7d7dc2e9f52d63b90bc7bd871a0c13c07ee8ce730d624f398b7acbc57054a
sha512: baf1a4a8b79a0289bb5cfee134e90ad7ee917b19be8be66ed333652442185ea8924969819b1b2be3dde166359d8a06ecaa6150fa4ac663853b28d62ee5a92d80
ssdeep: 384:A3K7pE7vPFJUOIg9J+ZE+IBU7c7G1Mrn1qYNMgbnJF7hXKHeBNgw9KsWjDlNpje:Ii67PFJagDQVxYnLtF90Gfmnpj+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Brneballernes
InternalName: Helsinkispostt5
FileVersion: 1.00
CompanyName: toponymalre
LegalTrademarks: Slumkvarte
Comments: Fogbankcoyni
ProductName: bunkebry
ProductVersion: 1.00
FileDescription: OVERCONFID
OriginalFilename: Helsinkispostt5.exe

Backdoor.Win32.Remcos.mxk also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42831691
McAfeeFareit-FRP!9F046AA9E467
CylanceUnsafe
K7AntiVirusTrojan ( 0056214b1 )
BitDefenderTrojan.GenericKD.42831691
K7GWTrojan ( 0056214b1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataWin32.Trojan-Downloader.Dagurleo.J0XR7S
KasperskyBackdoor.Win32.Remcos.mxk
AegisLabTrojan.Multi.Generic.4!c
AvastWin32:Trojan-gen
EmsisoftTrojan.GenericKD.42831691 (B)
F-SecureHeuristic.HEUR/AGEN.1046725
DrWebTrojan.Siggen9.18840
McAfee-GW-EditionFareit-FRP!9F046AA9E467
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1046725
ArcabitTrojan.Generic.D28D8F4B
ZoneAlarmBackdoor.Win32.Remcos.mxk
MicrosoftTrojan:Win32/Wacatac.C!ml
BitDefenderThetaGen:NN.ZevbaCO.34098.dm0@amGVRmci
MAXmalware (ai score=82)
MalwarebytesTrojan.GuLoader
ESET-NOD32a variant of Win32/Injector.EKYQ
eGambitUnsafe.AI_Score_98%
FortinetW32/GenKryptik.EFBB!tr
Ad-AwareTrojan.GenericKD.42831691
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Backdoor.Win32.Remcos.mxk?

Backdoor.Win32.Remcos.mxk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment