Backdoor

Backdoor.Win32.Remcos.nux information

Malware Removal

The Backdoor.Win32.Remcos.nux is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.nux virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.nux?


File Info:

crc32: 8C74E2F6
md5: 1a53e9230ba3bbd5969cc4499baaacdd
name: nw1.exe
sha1: 2a55286c66012cfb09151effabac6f8d54cc3ce1
sha256: bb9e4697a8a50fd18aafc26dbb19f7d13f51a8d650d67555f509e5f0aff1b824
sha512: 3dd984ec282e2bd4ce4e26aa2c84548b69ef695ef761498eb40a4484a9f5be08bca851ca3d868b8b353721b65fd3252a42ebe0ad5cfc70d0591b97b580752f3d
ssdeep: 1536:P6yQ+RRdgWQIK9/5Cr+myjzUau0LSr4tPn:TvJK9BCyBLJp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: overmatchokt
FileVersion: 1.00
CompanyName: SMART
Comments: SMART
ProductName: Auktionerneb8
ProductVersion: 1.00
FileDescription: spoonli
OriginalFilename: overmatchokt.exe

Backdoor.Win32.Remcos.nux also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33565223
Qihoo-360Win32/Backdoor.4b6
McAfeeArtemis!1A53E9230BA3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Remcos.m!c
K7AntiVirusTrojan ( 005635431 )
BitDefenderTrojan.GenericKD.33565223
K7GWTrojan ( 005635431 )
Cybereasonmalicious.c66012
ArcabitTrojan.Generic.D2002A27
TrendMicroTROJ_GEN.R057C0DCQ20
F-ProtW32/VBKrypt.AGE.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.ELFL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-7640581-0
KasperskyBackdoor.Win32.Remcos.nux
TencentWin32.Backdoor.Remcos.Dyql
EmsisoftTrojan.GenericKD.33565223 (B)
ComodoMalware@#3va4797frxftl
F-SecureTrojan.TR/Injector.ghkpo
DrWebTrojan.DownLoader33.21294
McAfee-GW-EditionFareit-FRL!1A53E9230BA3
FortinetW32/GuLoader.VHHX!tr
Trapminemalicious.high.ml.score
SophosMal/FareitVB-W
IkarusTrojan.VB.Crypt
CyrenW32/VBKrypt.AGE.gen!Eldorado
WebrootW32.Trojan.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
MicrosoftTrojan:Win32/Fareit.AE!MTB
ZoneAlarmBackdoor.Win32.Remcos.nux
Acronissuspicious
ALYacBackdoor.Remcos.A
Ad-AwareTrojan.GenericKD.33565223
MalwarebytesTrojan.GuLoader
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R057C0DCQ20
RisingBackdoor.Remcos!8.B89E (CLOUD)
GDataTrojan.GenericKD.33565223
BitDefenderThetaGen:NN.ZevbaF.34104.hm0@amb4!khi
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor.Win32.Remcos.nux?

Backdoor.Win32.Remcos.nux removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment