Backdoor

Backdoor.MSIL.Remcos.xq (file analysis)

Malware Removal

The Backdoor.MSIL.Remcos.xq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Remcos.xq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.Remcos.xq?


File Info:

name: 2D383AAC7D86426D42B5.mlw
path: /opt/CAPEv2/storage/binaries/087bb4ae6732d3cf9d995cd22c38a662853123b8c948449fc409ef30da36780c
crc32: BFEE9B3B
md5: 2d383aac7d86426d42b5660de1687feb
sha1: 3c9e36498bc70d47ef3960b23fa1e3ef1ad93f58
sha256: 087bb4ae6732d3cf9d995cd22c38a662853123b8c948449fc409ef30da36780c
sha512: c380070397a007128472db8d0d311915a1e98956f635a944df710adc49bd2b6022635ff0e75062c3592d4fad6555e08f71a528a2fa548ac4193f85a6043752c8
ssdeep: 196608:9SjXcezEhxr8YpnwwdJUHIs5mgBG+A2U1:9qXcezEhZppnwSJAIo5BG+A2I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1867633761182A053DC22A6399C86C8FBC751AF765EC0DAF3668F219F058F42942C67DF
sha3_384: 8cafab72aafec1829093dfab222bf247a500b28f366b7c2738eee0e7343fd2920800b0d331f230e949991e913bea5a25
ep_bytes: 68ecd44000e8f0ffffff000000000000
timestamp: 2011-11-06 08:39:01

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
LegalCopyright: Copyleft 1998-2016 by Don HO
ProductName: Notepad++
FileVersion: 7.82
ProductVersion: 7.82
InternalName: Notepad++
OriginalFilename: Notepad++.exe

Backdoor.MSIL.Remcos.xq also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.Remcos.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader32.52853
MicroWorld-eScanGen:Heur.PonyStealer.@p0@ouwX6thi
FireEyeGeneric.mg.2d383aac7d86426d
McAfeeFareit-FRI!2D383AAC7D86
CylanceUnsafe
Sangfor[MICROSOFT VISUAL BASIC 5.0]
K7AntiVirusTrojan ( 0055f5da1 )
AlibabaBackdoor:MSIL/Remcos.711341cc
K7GWTrojan ( 0055f5da1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZevbaF.34742.@p0@auwX6thi
CyrenW32/Injector.GH.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EKEH
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.VBGeneric-7563884-0
KasperskyBackdoor.MSIL.Remcos.xq
BitDefenderGen:Heur.PonyStealer.@p0@ouwX6thi
NANO-AntivirusTrojan.Win32.Zusy.gxoyon
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Backdoor.Remcos.Hrzc
Ad-AwareGen:Heur.PonyStealer.@p0@ouwX6thi
SophosMal/Generic-R + Mal/FareitVB-X
F-SecureHeuristic.HEUR/AGEN.1206728
VIPREGen:Heur.PonyStealer.@p0@ouwX6thi
McAfee-GW-EditionBehavesLike.Win32.Trojan.wc
EmsisoftGen:Heur.PonyStealer.@p0@ouwX6thi (B)
IkarusTrojan.VB.Agent
GDataGen:Heur.PonyStealer.@p0@ouwX6thi
JiangminBackdoor.MSIL.clhn
AviraHEUR/AGEN.1206728
MAXmalware (ai score=88)
ArcabitTrojan.PonyStealer.EFA7AD
ZoneAlarmBackdoor.MSIL.Remcos.xq
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.C1740422
ALYacGen:Heur.PonyStealer.@p0@ouwX6thi
MalwarebytesTrojan.Injector
YandexTrojan.GenAsa!gyz7L9LnQ20
SentinelOneStatic AI – Malicious PE
FortinetW32/Remcos.XQ!tr.bdr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Backdoor.MSIL.Remcos.xq?

Backdoor.MSIL.Remcos.xq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment