Backdoor

Backdoor.Win32.Remcos.tdm (file analysis)

Malware Removal

The Backdoor.Win32.Remcos.tdm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.tdm virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos.tdm?


File Info:

crc32: EB23994A
md5: 480c3643169681b464e69674dbe51f54
name: 480C3643169681B464E69674DBE51F54.mlw
sha1: b18541f09999c3237095b8a3f0f46377e3901840
sha256: 960787fe16f79546c7ad1096a3f5ab0a39cea0f4ad617720a133f1981e7121ab
sha512: 6deafe4e7aa3480e596ad675f036237b56b1ba807e99fbfb92e1be63a003b750dbe6c2d17ca8d0c93410a6f4a0266597c80ff6c5bea06b7abcc05d92a988f926
ssdeep: 1536:w7fqEJoXv2zeXuM3WNqXRXq4Ugpkh4D+n5UqwlKntEvM5BxBxkEEuC7A:w7q5Xv2EF6qpRUIkWDCM+xjKA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: Radiotelegrafi2
FileVersion: 1.00
CompanyName: Sisense
ProductName: LORENZKURVE
ProductVersion: 1.00
OriginalFilename: Radiotelegrafi2.exe

Backdoor.Win32.Remcos.tdm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.13332
ALYacTrojan.GenericKD.46544934
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPIL
APEXMalicious
AvastFileRepMalware
KasperskyBackdoor.Win32.Remcos.tdm
BitDefenderTrojan.GenericKD.46544934
MicroWorld-eScanTrojan.GenericKD.46544934
Ad-AwareTrojan.GenericKD.46544934
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaCO.34770.fm0@aeG5EPib
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
FireEyeGeneric.mg.480c3643169681b4
EmsisoftTrojan.GenericKD.46544934 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabTrojan.Win32.Remcos.m!c
GDataTrojan.GenericKD.46544934
McAfeeRDN/Generic.dx
MAXmalware (ai score=81)
YandexTrojan.AvsArher.bTx33N
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Remcos.TDM!tr.bdr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Backdoor.Win32.Remcos.tdm?

Backdoor.Win32.Remcos.tdm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment