Backdoor

Backdoor.Win32.Remcos.tvg malicious file

Malware Removal

The Backdoor.Win32.Remcos.tvg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.tvg virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Creates a copy of itself
  • Creates known Remcos directories and/or files
  • Creates known Remcos mutexes
  • Creates known Remcos registry keys

How to determine Backdoor.Win32.Remcos.tvg?


File Info:

name: 6C80199B7350BD470A75.mlw
path: /opt/CAPEv2/storage/binaries/1c08d0cd80763cdc8496a50f6f7f45cf36f014dcf54b937962ef86adc1b1c321
crc32: 5E2AA559
md5: 6c80199b7350bd470a75d2a95df7acf8
sha1: 41cbab77d01976646dbc790fae7ce2077fad9e81
sha256: 1c08d0cd80763cdc8496a50f6f7f45cf36f014dcf54b937962ef86adc1b1c321
sha512: ec388049c4a2c09dbd7dfc412ed2879d35b3ff04d0135236a197dfb8d01654cbc589ef1e7e509f6711aa86ed0e9cc31aea3c23ce45903ccc44bce5d33545365b
ssdeep: 12288:9hkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNyzD2Qp1tI8tJI:LRmJkcoQricOIQxiZY1WNyXPftx/I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FF4B021B5C69036C2B323B19E7EF76A9A3D79360336D19727C82D315EA05816B39733
sha3_384: b447b5451e4737177799d0534da81ed2e7a22526cd8794e1de7b9dbe49797a229ea137a9e398e2e02975a2161754fdd0
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Backdoor.Win32.Remcos.tvg also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.37780617
FireEyeGeneric.mg.6c80199b7350bd47
CAT-QuickHealTrojanPWS.AutoIt.Zbot.S
ALYacTrojan.GenericKD.37780617
CylanceUnsafe
ZillyaBackdoor.Remcos.Win32.4848
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/Predator.ali2000022
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.7d0197
CyrenW32/AutoIt.AO.gen!Eldorado
SymantecW32.Spyrat
ESET-NOD32a variant of Win32/Injector.Autoit.DCF
TrendMicro-HouseCallTROJ_GEN.R035C0PJ921
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Remcos.tvg
BitDefenderTrojan.GenericKD.37780617
AvastAutoIt:Injector-W [Trj]
TencentWin32.Backdoor.Remcos.Wrgq
SophosMal/Generic-S
TrendMicroTROJ_GEN.R035C0PJ921
McAfee-GW-EditionBehavesLike.Win32.AutoitDropper.bh
EmsisoftTrojan.GenericKD.37780617 (B)
IkarusTrojan.Win32.Injector
JiangminBackdoor.Remcos.dgw
AviraHEUR/AGEN.1116016
MicrosoftTrojan:Win32/Woreflint.A!cl
GDataTrojan.GenericKD.37780617
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AutoIt.R258728
McAfeeArtemis!6C80199B7350
MAXmalware (ai score=85)
VBA32Trojan.Autoit
MalwarebytesMalware.AI.2802601577
APEXMalicious
MaxSecureTrojan.Autoit.AZA
FortinetW32/Injector_Autoit.DCF!tr
AVGAutoIt:Injector-W [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor.Win32.Remcos.tvg?

Backdoor.Win32.Remcos.tvg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment