Backdoor.Remcos removal guide

Malware Removal

The Backdoor.Remcos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Backdoor.Remcos virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Bulgarian
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor.Remcos?


File Info:

crc32: F69920D5
md5: af59f263f83e0a307405ebd5286ec742
name: aniche.exe
sha1: 85493bd30905bd3b08642840c262ae11cad193b2
sha256: 5b34e36432d459fb7cb8cb7c6c68fb812d147a997278d8f3c38489b363f0c7bb
sha512: 9aa89881bf7d26e3284b3100310640b7925ba386cdc5796c43c155b176be0905f66dca8a02f3cf64f42daf1b78670c56418a34e02f144f2efbfda4b438a5562e
ssdeep: 49152:6CC0/1ZndNLjF3cNrDahr9VHawDXNND21:6a/zdNLtd1DdNy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Remcos also known as:

FireEyeGeneric.mg.af59f263f83e0a30
McAfeeArtemis!AF59F263F83E
CylanceUnsafe
AegisLabTrojan.Win32.Remcos.m!c
SangforMalware
Cybereasonmalicious.30905b
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Backdoor.Win32.Remcos.gen
RisingBackdoor.Remcos!8.B89E (TFE:4:Oe6GG6IyswM)
Endgamemalicious (high confidence)
McAfee-GW-EditionBehavesLike.Win32.Worm.tc
Trapminemalicious.high.ml.score
WebrootW32.Trojan.Gen
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
MalwarebytesBackdoor.Remcos
ESET-NOD32a variant of Win32/GenKryptik.EAJU
TrendMicro-HouseCallTROJ_GEN.R002H0DLJ19
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.EAJU!tr
BitDefenderThetaGen:NN.ZelphiF.33556.@HW@a8uKsnlG
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.a07

How to remove Backdoor.Remcos?

Backdoor.Remcos removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment