Backdoor

Backdoor:Win32/Rescoms.KD removal instruction

Malware Removal

The Backdoor:Win32/Rescoms.KD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rescoms.KD virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

cdn.discordapp.com

How to determine Backdoor:Win32/Rescoms.KD?


File Info:

crc32: 82B45460
md5: dcfec8793e20dae0f554342f2a8811a2
name: upload_file
sha1: 78912467c63086a0193af161dd5118b56b7dc82b
sha256: c2109f44d6d608cb821ea28489e75dbf7c7c18731918f8171bab7445db6e8599
sha512: 271a3b6f1d430f549c09c53e33331adb64058f62c41d36c471c375af74abdb7d69676e1410ad29ae43609139922cf77eff163a3bc05379d69930037ec19fe990
ssdeep: 24576:Sw9NREekcnEKus4FzHPSgonYl/Hhpng/2IKX:Sw5kdHqgb5X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Rescoms.KD also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.311210
FireEyeGen:Variant.Zusy.311210
McAfeeFareit-FVP!DCFEC8793E20
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Zusy.311210
K7GWTrojan-Downloader ( 0056c4691 )
K7AntiVirusTrojan-Downloader ( 0056c4691 )
TrendMicroTROJ_GEN.R002C0PHC20
BitDefenderThetaGen:NN.ZelphiF.34152.!KW@amb9NTki
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:HackTool.Win32.Agent.gen
AlibabaTrojanDownloader:Win32/Fareit.4a84fcbe
Ad-AwareGen:Variant.Zusy.311210
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1134473
FortinetW32/GenKryptik.DPIE!tr
SophosTroj/Inject-GHK
IkarusTrojan.Inject
CyrenW32/Trojan.EHZJ-6799
JiangminHackTool.Agent.dna
AviraHEUR/AGEN.1134473
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.Delf
ArcabitTrojan.Zusy.D4BFAA
AegisLabHacktool.Win32.Agent.3!c
MicrosoftBackdoor:Win32/Rescoms.KD
CynetMalicious (score: 90)
AhnLab-V3Malware/Win32.RL_Generic.R347772
ALYacGen:Variant.Zusy.311210
MalwarebytesTrojan.MalPack.SMY
PandaTrj/GdSda.A
ESET-NOD32Win32/TrojanDownloader.Delf.CZI
TrendMicro-HouseCallTROJ_GEN.R002C0PHC20
TencentWin32.Hacktool.Agent.Wwok
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Zusy.311210
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.Hacktool.ccf

How to remove Backdoor:Win32/Rescoms.KD?

Backdoor:Win32/Rescoms.KD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment