Backdoor

How to remove “Backdoor.MSIL.Remcos.pef”?

Malware Removal

The Backdoor.MSIL.Remcos.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Remcos.pef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.Remcos.pef?


File Info:

name: 81DE1B86A17A5EF760E7.mlw
path: /opt/CAPEv2/storage/binaries/6b6fe397f9be608c74d26a2a09258665ebd2fb73d5e743c61c6711c517b7d924
crc32: 53660360
md5: 81de1b86a17a5ef760e7cdf76eb6da1f
sha1: ca6662a7648fada19f08390661f0096b97d755af
sha256: 6b6fe397f9be608c74d26a2a09258665ebd2fb73d5e743c61c6711c517b7d924
sha512: ffd3308145ea495b618aa9483c2adbf02a2a27addb3c9438be9124d68582fc360b8a403a42667c6bb025a320ed82becf684164154d4e6102d8abae90c45408d7
ssdeep: 98304:bt0CqDjYwTjMYP+X//iXAwrx1zKoQXTtjMh7pg8VrWU2koE:mw6jMF//srzdQxMg8ZEkx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D163329450880E6E8648F3F65FEB7A002AF3CF75C55B2A27B497D1F33322D84564EA5
sha3_384: b783e0dc1f6a78164b5ec55e855961332fb8909df8b22873d12068b08e5592fac5291bb830d9ebfd5275cf71cdb52363
ep_bytes: 6878134000e8eeffffff000000000000
timestamp: 2013-12-30 11:03:48

Version Info:

Translation: 0x0404 0x04b0
Comments: givtigedr
CompanyName: Integra8
FileDescription: gluteope
ProductName: kouroiroo
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Tolerances
OriginalFilename: Tolerances.exe

Backdoor.MSIL.Remcos.pef also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeFareit-FRM!81DE1B86A17A
MalwarebytesTrojan.MalPack.VB.Generic
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005628bd1 )
K7GWTrojan ( 005628bd1 )
CrowdStrikewin/malicious_confidence_80% (D)
SymantecPacked.Generic.603
ESET-NOD32a variant of Win32/Injector.EKOS
APEXMalicious
ClamAVWin.Packed.Ponystealer-9798289-0
KasperskyHEUR:Backdoor.MSIL.Remcos.pef
BitDefenderGen:Heur.PonyStealer.9p0@qKup3Aub
NANO-AntivirusTrojan.Win32.Remcos.hcecsm
MicroWorld-eScanGen:Heur.PonyStealer.9p0@qKup3Aub
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.10b9a68d
Ad-AwareGen:Heur.PonyStealer.9p0@qKup3Aub
EmsisoftGen:Heur.PonyStealer.9p0@qKup3Aub (B)
DrWebTrojan.DownLoader33.9668
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.81de1b86a17a5ef7
SophosML/PE-A + Mal/FareitVB-AC
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.PonyStealer.9p0@qKup3Aub
JiangminBackdoor.MSIL.crtz
AviraHEUR/AGEN.1136442
Antiy-AVLTrojan/Generic.ASMalwS.300576E
ArcabitTrojan.PonyStealer.EACF37
MicrosoftTrojan:Win32/Remcos.RRR!MTB
AhnLab-V3Suspicious/Win.VBKrypt.X2058
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacGen:Heur.PonyStealer.9p0@qKup3Aub
MAXmalware (ai score=84)
CylanceUnsafe
RisingDownloader.Guloader!1.C916 (CLASSIC)
YandexTrojan.GenAsa!NbkgyjpS71M
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
FortinetW32/GuLoader.VHHQ!tr
BitDefenderThetaGen:NN.ZevbaF.34062.9p0@aKup3Aub
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.6a17a5
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.MSIL.Remcos.pef?

Backdoor.MSIL.Remcos.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment