Backdoor

About “Backdoor:Win32/Rescoms.A!rfn” infection

Malware Removal

The Backdoor:Win32/Rescoms.A!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rescoms.A!rfn virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Backdoor:Win32/Rescoms.A!rfn?


File Info:

crc32: 0E6C8B78
md5: 6a09d15a373b21b044fec9ab0d14240b
name: 6A09D15A373B21B044FEC9AB0D14240B.mlw
sha1: 9433e989f5ecdff49afa3e57aa231c33f77ee5e2
sha256: 742ba888bd9aa1412e47f81042c192f49233d7d8be1428a9446536f54be028b4
sha512: d25a761be82e62bf0af5f8d107ba700d6568121b5e5bed99364b2c05f246cc7b80ea38f2490ef8bd519523c97fa81b5fbfcd6ccac70958fe07a5ef63dd0e1b7b
ssdeep: 768:CYUnEzav81mxzPOn1fQyGg8WWF1Atm2FxSV8KlPixrTm+War1:CYUGDszPO1f7GgxWKm+tpq+Rr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Rescoms.A!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 001a8dec1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.42972
CynetMalicious (score: 100)
ALYacGeneric.Malware.SLcB.9F2023BF
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.61860
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 001a8dec1 )
Cybereasonmalicious.a373b2
CyrenW32/Downloader.I.gen!Eldorado
SymantecW32.Spyrat
ESET-NOD32a variant of Win32/Rescoms.B
APEXMalicious
AvastWin32:RemcosRAT-A [Trj]
ClamAVWin.Malware.Azden-7587127-0
KasperskyTrojan-Ransom.Win32.Blocker.jpnf
BitDefenderGeneric.Malware.SLcB.9F2023BF
NANO-AntivirusTrojan.Win32.Blocker.eoskuv
MicroWorld-eScanGeneric.Malware.SLcB.9F2023BF
TencentWin32.Trojan.Blocker.Wnmn
Ad-AwareGeneric.Malware.SLcB.9F2023BF
SophosML/PE-A + Troj/Remcos-DI
ComodoTrojWare.Win32.Rescoms.A@70v67g
BitDefenderThetaGen:NN.ZexaF.34670.cmGfaqeUSxpi
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_SOCMER.SM
McAfee-GW-EditionBehavesLike.Win32.Crack.nc
FireEyeGeneric.mg.6a09d15a373b21b0
EmsisoftGeneric.Malware.SLcB.9F2023BF (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.fex
WebrootW32.AGent.nescaw
AviraHEUR/AGEN.1115265
eGambitUnsafe.AI_Score_100%
MicrosoftBackdoor:Win32/Rescoms.A!rfn
AegisLabTrojan.Win32.Blocker.j!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Backdoor.Remcos.B
AhnLab-V3Backdoor/Win32.Farfli.C1526307
McAfeeArtemis!6A09D15A373B
MAXmalware (ai score=99)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallBKDR_SOCMER.SM
RisingBackdoor.Rescoms!8.B8A4 (CLOUD)
IkarusBackdoor.Remcos
FortinetW32/Generic.AP.292F5C!tr
AVGWin32:RemcosRAT-A [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Rescoms.HgIASPkA

How to remove Backdoor:Win32/Rescoms.A!rfn?

Backdoor:Win32/Rescoms.A!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment