Backdoor

Backdoor.Win32.Remcos.rbn removal tips

Malware Removal

The Backdoor.Win32.Remcos.rbn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.rbn virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Remcos.rbn?


File Info:

crc32: 6185C9B8
md5: 2b6936345d7c15ee613fb73328759f62
name: upload_file
sha1: 58858cc9b061900468e0aa63f2d1db5192374fa4
sha256: e0d73a9ec5eae9ad50f9c82237810cabb2717e0e48351ca30e56043acc1264e1
sha512: 9ba42fcfdd11e68ba3fd98d3d7fc07342374a54e1444097cf7a252b23ef42014b3ca66c2ebcd50cb26725fb125c5e800b8096d056ecf92a1db8b3ad7120e537f
ssdeep: 1536:ZCwzCaUz3BNwMmJ2Z801i+g6YCMFJbxtGS1645ZCD8ChZxnmZynVyOUfy:ow2z3BNb801hmfTE8ChZxnmgnVd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: Verge
InternalName: Cance7
FileVersion: 1.00
CompanyName: Verge
LegalTrademarks: Verge
Comments: Verge
ProductName: Verge
ProductVersion: 1.00
FileDescription: Verge
OriginalFilename: Cance7.exe

Backdoor.Win32.Remcos.rbn also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44092140
McAfeeRDN/Generic BackDoor
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0057144d1 )
BitDefenderTrojan.GenericKD.44092140
K7GWTrojan ( 0057144d1 )
BitDefenderThetaGen:NN.ZevbaCO.34570.km1@ae9PF5aj
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Remcos.rbn
AlibabaBackdoor:Win32/Remcos.ebe16836
ViRobotTrojan.Win32.Z.Wacatac.177528
Ad-AwareTrojan.GenericKD.44092140
SophosMal/Generic-S
F-SecureTrojan.TR/AD.VBCryptor.cglko
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/Generic BackDoor
EmsisoftTrojan.GenericKD.44092140 (B)
IkarusTrojan.Win32.Injector
AviraTR/AD.VBCryptor.cglko
MicrosoftTrojan:Win32/Bluteal!rfn
ArcabitTrojan.Generic.D2A0CAEC
ZoneAlarmBackdoor.Win32.Remcos.rbn
GDataTrojan.GenericKD.44092140
CynetMalicious (score: 90)
ALYacTrojan.GenericKD.44092140
MAXmalware (ai score=88)
ESET-NOD32a variant of Win32/Injector.ENQN
TrendMicro-HouseCallTROJ_GEN.R002H0DJG20
FortinetW32/ENQN!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.7e2

How to remove Backdoor.Win32.Remcos.rbn?

Backdoor.Win32.Remcos.rbn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment