Backdoor

Backdoor.Win32.Remcos.ncp (file analysis)

Malware Removal

The Backdoor.Win32.Remcos.ncp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.ncp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.ncp?


File Info:

crc32: C9FBC573
md5: ee446afedbe456c61a39751115b39b9f
name: 9a.exe
sha1: 065c4eb4572ee7aa7307a1e988ec795869f88273
sha256: 04a79f93d8f5e3a3e591c90358f08d92d6653eb23b18031f2db5123e7db0c151
sha512: 7c45d638f2b241ff9643c12c2d0e509fe7b809643e08d5bd831f31ca359f297145a0abb5da468d6f8daf2a45331e08adf8d6cc0f2c8d487086482c9b593effe3
ssdeep: 768:Qph4U1sBYiw8doG/1tPcZPkx9h+MmCDR8mraUy:Qph4U1yYi71HPcZPQzmgSmeUy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Fremtidsvision
FileVersion: 1.00
CompanyName: Ubisoft
ProductName: modemsi
ProductVersion: 1.00
FileDescription: Jerikaha
OriginalFilename: Fremtidsvision.exe

Backdoor.Win32.Remcos.ncp also known as:

McAfeeArtemis!EE446AFEDBE4
SangforMalware
K7AntiVirusTrojan ( 005624d51 )
K7GWTrojan ( 005624d51 )
Cybereasonmalicious.4572ee
Invinceaheuristic
F-ProtW32/Kryptik.BGA.gen!Eldorado
APEXMalicious
GDataWin32.Trojan.Agent.S7DBNQ
KasperskyBackdoor.Win32.Remcos.ncp
TencentWin32.Backdoor.Remcos.Amca
F-SecureTrojan.TR/BAS.Samca.ngrmc
DrWebTrojan.PackedENT.133
McAfee-GW-EditionFareit-FRP!EE446AFEDBE4
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.LokiBot
CyrenW32/Kryptik.BGA.gen!Eldorado
WebrootW32.Malware.Gen
AviraTR/BAS.Samca.ngrmc
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmBackdoor.Win32.Remcos.ncp
BitDefenderThetaGen:NN.ZevbaCO.34100.dm0@aSpxI4bi
MalwarebytesTrojan.GuLoader.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELAO
FortinetW32/GuLoader.VHHQ!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.8df

How to remove Backdoor.Win32.Remcos.ncp?

Backdoor.Win32.Remcos.ncp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment