Backdoor

About “Backdoor:Win32/Remcos.AC!rfn” infection

Malware Removal

The Backdoor:Win32/Remcos.AC!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Remcos.AC!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Remcos.AC!rfn?


File Info:

crc32: 8F933367
md5: c348af2ef14c9b4ba86f79be3cf248e7
name: property.exe
sha1: 73fa58137b382d6ca80107c0ded55fc5c4257632
sha256: dbad1bbb26395638bb2f447a800b3307319e8ebe4340d40357f13139a6fd6e1b
sha512: 064753f15769557461a4771b79d2fc7472d8fabdfbef733ee4aadcd25f793737cd4e2fa6b87e7f0985747ae5785e438bbf3569afa8a374122b213f5a4854f6ad
ssdeep: 12288:FQIOa9cWAHu1hXP7r9r/+ppppppppppppppppppppppppppppp0G:QW1q
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.0.0.0
InternalName: Royal.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft Corporation
Comments: Easy edit files and documents
ProductName: Microsoft Word
ProductVersion: 1.0.0.0
FileDescription: Microsoft Word
OriginalFilename: Royal.exe

Backdoor:Win32/Remcos.AC!rfn also known as:

MicroWorld-eScanGen:Heur.MSIL.Lagos.2
FireEyeGeneric.mg.c348af2ef14c9b4b
CAT-QuickHealBackdoor.Remcos
McAfeeArtemis!C348AF2EF14C
ALYacGen:Heur.MSIL.Lagos.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Ursu.4!c
SangforMalware
K7AntiVirusTrojan ( 00547d011 )
BitDefenderGen:Heur.MSIL.Lagos.2
K7GWTrojan ( 00547d011 )
Cybereasonmalicious.ef14c9
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Heur.MSIL.Lagos.2
KasperskyBackdoor.Win32.Remcos.eps
AlibabaBackdoor:Win32/Remcos.1f80ebaf
NANO-AntivirusTrojan.Win32.GenKryptik.fqlhvk
RisingBackdoor.Remcos!8.B89E (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#3594sgnyoo9ep
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Inject3.15950
ZillyaTrojan.GenKryptik.Win32.39704
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
MaxSecureTrojan.Malware.74037090.susgen
EmsisoftMalware.Generic.CN1 (A)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.UTUB-5994
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
ArcabitTrojan.MSIL.Lagos.2
ZoneAlarmBackdoor.Win32.Remcos.eps
MicrosoftBackdoor:Win32/Remcos.AC!rfn
AhnLab-V3Spyware/Win32.Zbot.R101367
MAXmalware (ai score=99)
Ad-AwareGen:Heur.MSIL.Lagos.2
MalwarebytesBackdoor.Remcos
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.CZLD
TencentWin32.Backdoor.Remcos.Swaq
YandexBackdoor.Remcos!
IkarusTrojan.MSIL.Krypt
eGambitUnsafe.AI_Score_99%
FortinetMSIL/GenKryptik.CYBS!tr
BitDefenderThetaGen:NN.ZemsilF.34090.Uq3@aOrGu!h
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.a3b

How to remove Backdoor:Win32/Remcos.AC!rfn?

Backdoor:Win32/Remcos.AC!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment