Backdoor

Should I remove “Backdoor.Win32.Remcos.mrc”?

Malware Removal

The Backdoor.Win32.Remcos.mrc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.mrc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.mrc?


File Info:

crc32: 2B95F058
md5: 2ec84c17b0ea64145f1f86fd5b75f9dc
name: details.exe
sha1: 9d3bfa37007f1a958210deda3de68649eff5d537
sha256: a2a30f55d42a5d827dcac465284e5a54b33554c261d27254380357e5174947b8
sha512: bf7e827c5014a2e211aa377cba16d09135bc374a2f538a0bdb35cca21875b01f9dad355d5006be739e735090f77a6cf0dcf1b2a930bc4327e63cb4ff40216599
ssdeep: 768:J6AUKnPwwO6MlfA9S8LVlnVd2FpyJ7vnJ6AU:J6AN5YfsSG7n2FpQh6A
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
LegalCopyright: Frikendt
InternalName: DEFORMALIZE
FileVersion: 1.00.0001
CompanyName: freedOM
LegalTrademarks: Pragmatikeres
Comments: diazoamino
ProductName: linage
ProductVersion: 1.00.0001
FileDescription: FLYT
OriginalFilename: DEFORMALIZE.exe

Backdoor.Win32.Remcos.mrc also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.Siggen9.17760
MicroWorld-eScanTrojan.GenericKD.33515800
McAfeeArtemis!2EC84C17B0EA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00561de71 )
BitDefenderTrojan.GenericKD.33515800
K7GWTrojan ( 00561de71 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojan.Win32.WACATAC.THCOEBO
BitDefenderThetaGen:NN.ZevbaF.34098.gm0@aaoLvLhG
F-ProtW32/Injector.ZV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.33515800
KasperskyBackdoor.Win32.Remcos.mrc
AlibabaBackdoor:Win32/Remcos.ac834f3e
NANO-AntivirusTrojan.Win32.Remcos.hefwwa
AegisLabTrojan.Win32.Remcos.m!c
TencentWin32.Backdoor.Remcos.Hvto
EmsisoftTrojan.GenericKD.33515800 (B)
ComodoMalware@#1i1527wu8s9os
F-SecureTrojan.TR/Injector.hfzsb
McAfee-GW-EditionRDN/Generic BackDoor
Trapminemalicious.high.ml.score
SophosMal/Generic-S
CyrenW32/Injector.ZV.gen!Eldorado
JiangminBackdoor.Remcos.atb
AviraTR/Injector.hfzsb
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1FF6918
ZoneAlarmBackdoor.Win32.Remcos.mrc
TACHYONBackdoor/W32.VB-Remcos.110592
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacBackdoor.Remcos.A
MAXmalware (ai score=99)
Ad-AwareTrojan.GenericKD.33515800
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKWS
TrendMicro-HouseCallTrojan.Win32.WACATAC.THCOEBO
RisingBackdoor.Remcos!8.B89E (CLOUD)
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.77156626.susgen
FortinetW32/EKWS!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Win32/Backdoor.b91

How to remove Backdoor.Win32.Remcos.mrc?

Backdoor.Win32.Remcos.mrc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment