Backdoor

Backdoor.Win32.Remcos.skq (file analysis)

Malware Removal

The Backdoor.Win32.Remcos.skq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.skq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Hungarian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.skq?


File Info:

crc32: BE82CB7E
md5: b75b990ac5990f1b6b0127540de4ec30
name: B75B990AC5990F1B6B0127540DE4EC30.mlw
sha1: 66dd5a9d359faf4abdff9b53b8e96280eff58038
sha256: f7aba1c5e66938efc7a722f98344a70a2443391668283f08da1202bde6c9b925
sha512: e2009b8e6ad35c60f08efb6514c18c650929f343b01a14f2aab8d5eaec880520c67bcf6795ed21be8c462a2c32eb31e80a7a3a1c9767776ce18f208b4f89ff45
ssdeep: 1536:61oJy7aGTvIaUZNcddsm3dE+WE2i5JjyI+h91mR4E:6v7aGTUcddaMrjyIA1jE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x040e 0x04b0
LegalCopyright: Copyright (C) AC
InternalName: OPSGTEBARBA
FileVersion: 1.00
CompanyName: AC
LegalTrademarks: Copyright (C) AC
Comments: AC
ProductName: AC
ProductVersion: 1.00
FileDescription: AC
OriginalFilename: OPSGTEBARBA.exe

Backdoor.Win32.Remcos.skq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.221
MicroWorld-eScanTrojan.GenericKD.36437670
FireEyeGeneric.mg.b75b990ac5990f1b
CAT-QuickHealTrojan.Vbobfuse
Qihoo-360Win32/Backdoor.Remcos.HgIASQYA
ALYacBackdoor.Remcos.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005788e61 )
BitDefenderTrojan.GenericKD.36437670
K7GWTrojan ( 005788e61 )
Cybereasonmalicious.ac5990
BitDefenderThetaGen:NN.ZevbaCO.34608.fm0@a4jNcWpG
CyrenW32/VBKrypt.ARZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DC321
AvastWin32:Trojan-gen
ClamAVWin.Packed.Filerepmalware-9838753-0
KasperskyBackdoor.Win32.Remcos.skq
AlibabaBackdoor:Win32/Remcos.1d17e44d
NANO-AntivirusTrojan.Win32.PackedENT.inyruj
ViRobotTrojan.Win32.Z.Agent.94208.EEL
AegisLabTrojan.Win32.Generic.4!c
RisingDownloader.Guloader!1.D2F0 (CLOUD)
Ad-AwareTrojan.GenericKD.36437670
SophosMal/Generic-S
ComodoMalware@#3ccj5owsm1sgo
F-SecureTrojan.TR/Injector.ckgpx
TrendMicroTROJ_GEN.R002C0DC321
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nm
EmsisoftTrojan.Injector (A)
IkarusTrojan.VB.Crypt
WebrootW32.Malware.Gen
AviraTR/Injector.ckgpx
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/VBObfuse.SS!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22BFEA6
AhnLab-V3Malware/Win32.RL_Generic.R369317
ZoneAlarmBackdoor.Win32.Remcos.skq
GDataTrojan.GenericKD.36437670
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Injector.EOSK
McAfeePWS-FCUB!B75B990AC599
MAXmalware (ai score=99)
MalwarebytesTrojan.MalPack.VB
PandaTrj/Agent.PM
APEXMalicious
TencentWin32.Backdoor.Remcos.Pezj
YandexTrojan.AvsArher.bTx33N
FortinetW32/Injector.EOTL!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Remcos.skq?

Backdoor.Win32.Remcos.skq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment