Categories: Backdoor

How to remove “Backdoor.Win32.Remcos”?

The Backdoor.Win32.Remcos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Bulgarian
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Remcos?


File Info:

crc32: F69920D5md5: af59f263f83e0a307405ebd5286ec742name: aniche.exesha1: 85493bd30905bd3b08642840c262ae11cad193b2sha256: 5b34e36432d459fb7cb8cb7c6c68fb812d147a997278d8f3c38489b363f0c7bbsha512: 9aa89881bf7d26e3284b3100310640b7925ba386cdc5796c43c155b176be0905f66dca8a02f3cf64f42daf1b78670c56418a34e02f144f2efbfda4b438a5562essdeep: 49152:6CC0/1ZndNLjF3cNrDahr9VHawDXNND21:6a/zdNLtd1DdNytype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Remcos also known as:

FireEye Generic.mg.af59f263f83e0a30
McAfee Artemis!AF59F263F83E
Cylance Unsafe
AegisLab Trojan.Win32.Remcos.m!c
Sangfor Malware
Cybereason malicious.30905b
Symantec ML.Attribute.HighConfidence
Kaspersky HEUR:Backdoor.Win32.Remcos.gen
Rising Backdoor.Remcos!8.B89E (TFE:4:Oe6GG6IyswM)
Endgame malicious (high confidence)
McAfee-GW-Edition BehavesLike.Win32.Worm.tc
Trapmine malicious.high.ml.score
Webroot W32.Trojan.Gen
ZoneAlarm HEUR:Backdoor.Win32.Remcos.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Acronis suspicious
Malwarebytes Backdoor.Remcos
ESET-NOD32 a variant of Win32/GenKryptik.EAJU
TrendMicro-HouseCall TROJ_GEN.R002H0DLJ19
SentinelOne DFI – Suspicious PE
Fortinet W32/GenKryptik.EAJU!tr
BitDefenderTheta Gen:NN.ZelphiF.33556.@HW@a8uKsnlG
Paloalto generic.ml
CrowdStrike win/malicious_confidence_80% (W)
Qihoo-360 Win32/Backdoor.a07

How to remove Backdoor.Win32.Remcos?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan:Win32/Remcos!pz (file analysis)

The Trojan:Win32/Remcos!pz is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

About “Jalapeno.1619” infection

The Jalapeno.1619 is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

Babar.213996 removal tips

The Babar.213996 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Malware.AI.2248263649 (file analysis)

The Malware.AI.2248263649 is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

About “Trojan.Dropper.Agent.AKK” infection

The Trojan.Dropper.Agent.AKK is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

Malware.AI.2972915474 malicious file

The Malware.AI.2972915474 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago