Backdoor

How to remove “Backdoor.Win32.Remcos.nfk”?

Malware Removal

The Backdoor.Win32.Remcos.nfk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.nfk virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.nfk?


File Info:

crc32: F2FB0E28
md5: 06df59c7fec8d6f90965ff158e422136
name: 06DF59C7FEC8D6F90965FF158E422136.mlw
sha1: 4852130c05e9c3d84ad1bd865ca5efb7500586f7
sha256: 6d023845dcdd11e8f334c4483a8becde8bef05bd6afc0d17d713c71ab381dc01
sha512: 18d8d1871168fb8945ac2eb3350ced93bf7069ed4c9770e762a86a220a6ab8f9f868d64cb625cf83cab742e19fa2937f0d7d49bd6a6925e84ec732754b73dd5d
ssdeep: 768:+p11dGuQ3UNM8nU14KFthUIqIrENBWQmDGRpnPd:+p11dFN73KFthUILoi0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Mozilla
InternalName: 7zS.sfx
FileVersion: 18.05
CompanyName: Mozilla
LegalTrademarks:
ProductName: Firefox
ProductVersion: 18.05
FileDescription: Firefox
OriginalFilename: 7zS.sfx.exe

Backdoor.Win32.Remcos.nfk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.20719
MicroWorld-eScanTrojan.GenericKD.33541980
FireEyeGeneric.mg.06df59c7fec8d6f9
CAT-QuickHealTrojan.Agent
Qihoo-360Win32/Backdoor.5fa
McAfeeFareit-FRJ!06DF59C7FEC8
CylanceUnsafe
VIPREWin32.Malware!Drop
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.33541980
K7GWTrojan ( 005627e81 )
K7AntiVirusTrojan ( 005627e81 )
BitDefenderThetaGen:NN.ZevbaF.34804.cn2@aqLnv6ii
CyrenW32/Trojan.MVLD-3211
SymantecML.Attribute.HighConfidence
ZonerTrojan.Win32.90053
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.THCBABO
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.Remcos-7619633-0
KasperskyBackdoor.Win32.Remcos.nfk
AlibabaBackdoor:Win32/Remcos.90d16f00
NANO-AntivirusTrojan.Win32.Remcos.hfkpua
RisingBackdoor.Remcos!8.B89E (KTSE)
Ad-AwareTrojan.GenericKD.33541980
EmsisoftTrojan-Downloader.Agent (A)
F-SecureTrojan.TR/Agent.ifuhtv
TrendMicroTrojanSpy.Win32.FAREIT.THCBABO
McAfee-GW-EditionFareit-FRJ!06DF59C7FEC8
SophosMal/Generic-S + Mal/Generic-L
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Remcos.bwr
AviraTR/Agent.ifuhtv
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
MicrosoftTrojan:Win32/Skeeyah.A!MTB
ArcabitTrojan.Generic.D1FFCF5C
ZoneAlarmBackdoor.Win32.Remcos.nfk
GDataWin32.Trojan-Downloader.Dagurleo.TJ1MTR
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Injector.C3889613
VBA32Backdoor.Remcos
ALYacTrojan.GenericKD.33541980
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.VB
PandaTrj/WLT.F
ESET-NOD32Win32/TrojanDownloader.Agent.EWX
TencentWin32.Trojan.Inject.Auto
IkarusTrojan.Win32.Injector
eGambitPE.Heur.InvalidSig
FortinetW32/Injector.ELAS!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.7fec8d
Paloaltogeneric.ml
MaxSecureTrojan.Malware.77943840.susgen

How to remove Backdoor.Win32.Remcos.nfk?

Backdoor.Win32.Remcos.nfk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment