Backdoor

Backdoor.Win32.Remcos.neg removal tips

Malware Removal

The Backdoor.Win32.Remcos.neg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.neg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.neg?


File Info:

crc32: C75D545E
md5: d534737eab45af28c56097cb52ef54c9
name: file.exe
sha1: 2cef8fda06a8595eafe20711f25ecd160de6634d
sha256: 64551b04da5c87e5ecaa8e315cdd186fac570fbf47ad3cf5eb3daf4b1138859d
sha512: a0f7ad10fee1c632d1ba279a5d86b64cd2881997b85a03968ba72024dda41dba1b6d0a17c6618e15056d75445203085cce4ad565c425462b3c08ec02d432cf68
ssdeep: 768:Tc6gba1b9V80VqcE/3XlkaukKrkqq7uJKrAQJxK:T5Oa1/8DcEPqaudrkqNJsAR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Veletm5
FileVersion: 1.00
CompanyName: Ubisoft
ProductName: Armvridningsun
ProductVersion: 1.00
FileDescription: analeroti
OriginalFilename: Veletm5.exe

Backdoor.Win32.Remcos.neg also known as:

DrWebTrojan.PackedENT.133
MicroWorld-eScanTrojan.GenericKD.33538321
Qihoo-360Trojan.Generic
McAfeeArtemis!D534737EAB45
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056256c1 )
BitDefenderTrojan.GenericKD.33538321
K7GWTrojan ( 0056256c1 )
BitDefenderThetaGen:NN.ZevbaCO.34100.dm0@a8nDn7fi
F-ProtW32/Injector.AAJ.gen!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.33538321
KasperskyBackdoor.Win32.Remcos.neg
AlibabaTrojan:Win32/vbcrypt.ali2000008
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.33538321
SophosMal/FareitVB-W
F-SecureTrojan.TR/Injector.wccip
TrendMicroTROJ_GEN.R011C0DCE20
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.33538321 (B)
IkarusTrojan.VB.Crypt
CyrenW32/Injector.AAJ.gen!Eldorado
WebrootW32.Trojan.GenKD
AviraTR/Injector.wccip
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
ArcabitTrojan.Generic.D1FFC111
ZoneAlarmBackdoor.Win32.Remcos.neg
MicrosoftTrojan:Win32/Injector.MU!MTB
AhnLab-V3Trojan/Win32.VBKrypt.C4013381
ALYacBackdoor.Remcos.A
MAXmalware (ai score=89)
MalwarebytesTrojan.GuLoader.VB
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.ELAX
TrendMicro-HouseCallTROJ_GEN.R011C0DCE20
TencentWin32.Backdoor.Remcos.Wpiy
FortinetW32/ELAX!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.77515295.susgen

How to remove Backdoor.Win32.Remcos.neg?

Backdoor.Win32.Remcos.neg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment