Backdoor

Backdoor.Win32.Remcos.mla removal tips

Malware Removal

The Backdoor.Win32.Remcos.mla is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.mla virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.mla?


File Info:

crc32: C1951496
md5: 6d88e0a1cdb5492bfac2e4a00843852a
name: ds.exe
sha1: 7180d99a3e8c506c8e544873a6b84624d027711a
sha256: e3347387ef7a0be144e9a52841a72b34a4851af8110fb77ad28e3c68811cfd5b
sha512: 8e97a4b151c38ce10c5b80ef52f100cf6c6335b1a0f66e594dbc236c1b7092c3ac7e70267ec252493139906570580b2c85549d896c9423176eed6d38e8bbb5e9
ssdeep: 768:BqQyFEKbftGTLWv+0lcqcE662iMlNajbftGTLWv+0lcqcE662i5lNakbi8YAK26:UQ+bL+KRlJHMjkbL+KRlJH5jZYAA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: Anim
FileVersion: 1.00
OriginalFilename: Anim.exe
ProductName: PEDANTIS

Backdoor.Win32.Remcos.mla also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Jaik.39305
FireEyeGen:Variant.Jaik.39305
McAfeeRDN/Generic.dx
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056187f1 )
BitDefenderGen:Variant.Jaik.39305
K7GWTrojan ( 0056187f1 )
TrendMicroTROJ_GEN.R011C0PC220
BitDefenderThetaGen:NN.ZevbaCO.34096.em0@aS6ciVei
CyrenW32/Trojan.VXHB-5207
SymantecTrojan.Gen.2
APEXMalicious
GDataGen:Variant.Jaik.39305
KasperskyBackdoor.Win32.Remcos.mla
AlibabaTrojan:Win32/vbcrypt.ali2000008
RisingBackdoor.Remcos!8.B89E (CLOUD)
Ad-AwareGen:Variant.Jaik.39305
SophosMal/FareitVB-W
F-SecureTrojan.TR/Injector.yfqrj
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Jaik.39305 (B)
WebrootW32.Trojan.TR.Injector.yfqrj
AviraTR/Injector.yfqrj
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
ArcabitTrojan.Jaik.D9989
ZoneAlarmBackdoor.Win32.Remcos.mla
MicrosoftTrojan:Win32/Occamy.C
ALYacGen:Variant.Jaik.39305
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.VB.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKUU
TrendMicro-HouseCallTROJ_GEN.R011C0PC220
TencentWin32.Backdoor.Remcos.Wrqu
YandexTrojan.Injector!7g7xNfdILxw
FortinetW32/EKUU!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.Remcos.mla?

Backdoor.Win32.Remcos.mla removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment