Backdoor

Backdoor.Win32.Remcos.tkm removal guide

Malware Removal

The Backdoor.Win32.Remcos.tkm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.tkm virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.Remcos.tkm?


File Info:

crc32: CEC41E56
md5: d4d15d78e292869c5488ddc05e227f10
name: D4D15D78E292869C5488DDC05E227F10.mlw
sha1: 9d0416d6bf68ed1a088c010046cd2fad4b7d32dd
sha256: fa66310d09441ef074ebec4df91a8210a710a44c5ddb7d7040a1aabce1679f59
sha512: 52619ebcec38ceec0a73e795cd5068fc7457b339931cd46bfa396e1c463cecf29c48106a6b30f6e0f45fce0a981c18bd436954b7e4559f25b5cf2705d83e85a3
ssdeep: 24576:rAOcZAhwaU3m5RJ8+LhdXpWxIhjKLeZGEyYDSZaC/+YxkJkscoPE+FQYcXGI9y:tuaC3+z5yFeZGEytZ/+wodco8+6T9y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Remcos.tkm also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Remcos.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Remcos
ALYacTrojan.GenericKD.46710663
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/Remcos.13f85ec1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6bf68e
CyrenW32/S-536dd2d1!Eldorado
SymantecTrojan.Gen.MBT
ZonerTrojan.Win32.92739
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Nanocore-9171333-0
KasperskyBackdoor.Win32.Remcos.tkm
BitDefenderAIT.Heur.Lisk.1.3FF41719.Gen
MicroWorld-eScanTrojan.GenericKD.37373616
Ad-AwareTrojan.GenericKD.37373616
SophosML/PE-A
ComodoMalware@#2ms1bgkoxlavr
TrendMicroTROJ_GEN.R049C0PH221
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.d4d15d78e292869c
EmsisoftTrojan.GenericKD.37373616 (B)
SentinelOneStatic AI – Suspicious SFX
AviraBDS/Remcos.hocie
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
GridinsoftRansom.Win32.Wacatac.oa!s1
ZoneAlarmBackdoor.Win32.Remcos.tkm
GDataTrojan.GenericKD.37373616
AhnLab-V3Dropper/Win.Generic.C4572785
McAfeeArtemis!D4D15D78E292
MAXmalware (ai score=80)
VBA32Trojan.Woreflint
MalwarebytesTrojan.Dropper.SFX
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R049C0PH221
IkarusTrojan-Spy.FormBook
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASZsA

How to remove Backdoor.Win32.Remcos.tkm?

Backdoor.Win32.Remcos.tkm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment