Backdoor

How to remove “Backdoor.Remcos.NSIS”?

Malware Removal

The Backdoor.Remcos.NSIS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Remcos.NSIS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Backdoor.Remcos.NSIS?


File Info:

name: F99CB9FDA1D84BFDDD80.mlw
path: /opt/CAPEv2/storage/binaries/becc4959dc9e40178465b712cdc80ef4b5a15ea2df4a732ae9f731ddd8488548
crc32: CF7C7EBE
md5: f99cb9fda1d84bfddd80bfff440b2935
sha1: b2b2e63831b18c948543cadae5d906f8682edbd1
sha256: becc4959dc9e40178465b712cdc80ef4b5a15ea2df4a732ae9f731ddd8488548
sha512: 9d8e9c1da8b1d4031767fc5e8358a5666245016ce692abaea0839d2858b82d84e9f5a1ff288d2b86a6a3246f9185d794c05ab36bd4cef242f10cd5f3fd674c20
ssdeep: 6144:VsxjyTmjTQSKoBOgIgdM4LFc2WahfhWUrdle:oOmPnVBOmdJCahfhWMg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C224016724F684DBE05E577288B3DB72B7B5AD4A5260055BB7863F273831343883F18A
sha3_384: 2a9f22c81fd07fa9c761d44ec9ea0436dab71b5aeaa8cf1635b8764ab5c2f989cc557a56bfa8118ce86534e0aa9378a1
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Backdoor.Remcos.NSIS also known as:

LionicTrojan.Win32.Agensla.i!c
Elasticmalicious (high confidence)
DrWebTrojan.Loader.798
MicroWorld-eScanTrojan.GenericKD.46403399
FireEyeGeneric.mg.f99cb9fda1d84bfd
McAfeeArtemis!F99CB9FDA1D8
CylanceUnsafe
ZillyaTrojan.Injector.Win32.946032
SangforTrojan.Win32.Agensla.gen
K7AntiVirusTrojan ( 0057ccde1 )
AlibabaTrojanPSW:Win32/Agensla.70d4398c
K7GWTrojan ( 0057ccde1 )
ArcabitTrojan.Generic.D2C40F47
CyrenW32/Ninjector.B!Camelot
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
BitDefenderTrojan.GenericKD.46403399
AvastNSIS:PWSX-gen [Trj]
TencentWin32.Trojan-qqpass.Qqrob.Efay
Ad-AwareTrojan.GenericKD.46403399
EmsisoftTrojan.GenericKD.46403399 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.121218.susgen
AviraHEUR/AGEN.1143325
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataTrojan.GenericKD.46403399
CynetMalicious (score: 99)
AhnLab-V3Suspicious/Win.Evo-gen.C4496582
ALYacTrojan.GenericKD.46403399
MAXmalware (ai score=88)
VBA32TrojanPSW.Agensla
MalwarebytesBackdoor.Remcos.NSIS
APEXMalicious
RisingTrojan.Injector/NSIS!1.D63B (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetNSIS/Injector.EPJF!tr
WebrootW32.Trojan.Gen
AVGNSIS:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Remcos.NSIS?

Backdoor.Remcos.NSIS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment