Backdoor

About “Backdoor.Win32.Remcos.nwd” infection

Malware Removal

The Backdoor.Win32.Remcos.nwd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.nwd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.nwd?


File Info:

crc32: C8B3A6EA
md5: 14141aaa6892a27c3b6c627bfeb75167
name: nass.exe
sha1: 17c911d3dc619ac997278f18e72ff8ca218fe396
sha256: 98f58666a225a17e19aac47c6d4169aff52fc92a557165f453121ddee78351ce
sha512: 058dba1625c0e013042e1670463d7ab80ff6d469bf5c5a61a8a00bb89a5b2e7a808fb6a237e7efab4dcf7de2837faafb022fe90b93be5a2ba3a60f4b74354f72
ssdeep: 3072:t+mRY0QIG4ahlYoN/+rnuHx1NTTBd0g/MCzO2f9:t+mNQKGlJ/++
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Incorrupti1
FileVersion: 1.00
CompanyName: K-MART
Comments: K-MART
ProductName: SEMICA
ProductVersion: 1.00
FileDescription: Peroxi
OriginalFilename: Incorrupti1.exe

Backdoor.Win32.Remcos.nwd also known as:

DrWebTrojan.DownLoader33.21360
MicroWorld-eScanTrojan.GenericKD.33565014
Qihoo-360Win32/Backdoor.2b2
McAfeeArtemis!14141AAA6892
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.33565014
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0DCQ20
BitDefenderThetaGen:NN.ZevbaF.34104.im0@aqTsL5gi
F-ProtW32/Trojan.DLW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.33565014
KasperskyBackdoor.Win32.Remcos.nwd
AlibabaTrojan:Win32/vbcrypt.ali2000008
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Backdoor.Remcos.Duwa
Ad-AwareTrojan.GenericKD.33565014
SophosMal/FareitVB-W
ComodoMalware@#3rrn14092e6vo
F-SecureTrojan.TR/Injector.lkpde
McAfee-GW-EditionBehavesLike.Win32.Fareit.cz
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33565014 (B)
CyrenW32/Trojan.DLW.gen!Eldorado
AviraTR/Injector.lkpde
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
ArcabitTrojan.Generic.D2002956
ZoneAlarmBackdoor.Win32.Remcos.nwd
MicrosoftTrojan:Win32/Fareit.AE!MTB
Acronissuspicious
ALYacTrojan.GenericKD.33565014
MAXmalware (ai score=87)
VBA32BScope.Trojan.Fareit
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELFS
TrendMicro-HouseCallTROJ_GEN.R002C0DCQ20
RisingBackdoor.Remcos!8.B89E (CLOUD)
IkarusTrojan.VB.Crypt
FortinetW32/ELFS.FRL!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Backdoor.Win32.Remcos.nwd?

Backdoor.Win32.Remcos.nwd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment