Backdoor

About “Backdoor.Win32.Remcos.mjf” infection

Malware Removal

The Backdoor.Win32.Remcos.mjf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.mjf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.mjf?


File Info:

crc32: 8A15E8E7
md5: 2d7408663655e9852b9d6ab275781e73
name: server.bin
sha1: e862266816840ee99425537f914d19edc11cd6ed
sha256: 356847fbca92361b40dd9b1f114fb0760dc1c5ac5fb33811c7f4664664b7a990
sha512: 723a897ed6828940cf4b384cef1d32e986c189e89dc21b61aee873018ee6576969326be6ef1a249434abb5ecefcaeba453245cd0f467f41c9e3c32f6ea9bb786
ssdeep: 768:fj5IzecBmYvVAU6L1/MoOtnps08EhS8bqs4nB:fdoxv6PLRMjnps8hS84B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: averte
FileVersion: 1.00
OriginalFilename: averte.exe
ProductName: nefariou

Backdoor.Win32.Remcos.mjf also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.PackedENT.133
MicroWorld-eScanTrojan.GenericKD.42697558
FireEyeTrojan.GenericKD.42697558
ALYacTrojan.GenericKD.42697558
MalwarebytesTrojan.MalPack.VB
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42697558
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojanSpy.Win32.FAREIT.SMTHD.hp
BitDefenderThetaGen:NN.ZevbaCO.34096.dm0@aGsNb!ii
CyrenW32/Kryptik.BCI.gen!Eldorado
SymantecInfostealer
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42697558
KasperskyBackdoor.Win32.Remcos.mjf
NANO-AntivirusTrojan.Win32.Remcos.hcpucf
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Backdoor.Remcos.Htmi
Ad-AwareTrojan.GenericKD.42697558
SophosMal/FareitVB-W
McAfee-GW-EditionFareit-FRM!2D7408663655
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.42697558 (B)
IkarusTrojan.VB.Crypt
F-ProtW32/Kryptik.BCI.gen!Eldorado
JiangminBackdoor.Remcos.arc
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D28B8356
ZoneAlarmBackdoor.Win32.Remcos.mjf
MicrosoftTrojan:Win32/Tiggre!rfn
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=89)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKUB
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMTHD.hp
RisingBackdoor.Remcos!8.B89E (CLOUD)
FortinetW32/EKUB!tr
AVGWin32:Trojan-gen

How to remove Backdoor.Win32.Remcos.mjf?

Backdoor.Win32.Remcos.mjf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment