Backdoor

What is “Backdoor:Win32/Rescoms”?

Malware Removal

The Backdoor:Win32/Rescoms is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rescoms virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)

How to determine Backdoor:Win32/Rescoms?


File Info:

crc32: 911BCDED
md5: 73454d4bab0cd79409efb66555cdcd8a
name: 7024d4bd829072b1.exe
sha1: 172c2ad3e0acdc4724ec08078598b7dcab1589ed
sha256: bd68c139a95fc305ceb7c205208c9bc0c77e22fe1333cddac3fa73a7231e6a3d
sha512: 9fbf8187b30ccdd019b81da85c4ab74929b6ede117894e8814455c53462f345fee0f24c951121bb452ca5689fbcc3625fe8db0468d8cfaedbb888da12d3a949d
ssdeep: 1536:ghhW0YTGZWdVseJxaM9kraLdV2QkQ1TbPX8IHOCkIsI4ESHNTh9E+JP19qkP60rf:mhzYTGWVvJ8f2v1TbPzuMsIFSHNThy+j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Rescoms also known as:

BkavW32.CoiminerRMI.Trojan
MicroWorld-eScanTrojan.Inject.BDT
FireEyeGeneric.mg.73454d4bab0cd794
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FOFQ!73454D4BAB0C
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004f67651 )
BitDefenderTrojan.Inject.BDT
K7GWTrojan ( 004f67651 )
Cybereasonmalicious.bab0cd
TrendMicroBKDR_SOCMER.SM
F-ProtW32/Injector.IXO
SymantecInfostealer!im
APEXMalicious
ClamAVWin.Malware.Rescoms-6598304-0
GDataWin32.Malware.Bucaspys.B
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.AD.erfeyu
ViRobotTrojan.Win32.Agent.94208.EA
SUPERAntiSpywareBackdoor.Remcos/Variant
TencentMalware.Win32.Gencirc.10b097e0
Endgamemalicious (high confidence)
EmsisoftTrojan.Inject.BDT (B)
ComodoTrojWare.Win32.Rescoms.A@70v67g
F-SecureHeuristic.HEUR/AGEN.1115265
DrWebTrojan.DownLoader25.11684
ZillyaTrojan.Agent.Win32.742092
Invinceaheuristic
MaxSecureTrojan.Malware.7164915.susgen
Trapminemalicious.high.ml.score
SophosTroj/Remcos-DI
IkarusBackdoor.Win32.Rescoms
CyrenW32/Injector.AKNB-1880
JiangminTrojan.Generic.bgmwv
WebrootW32.Malware.gen
AviraHEUR/AGEN.1115265
MAXmalware (ai score=84)
MicrosoftBackdoor:Win32/Rescoms
ArcabitTrojan.Inject.BDT
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Rescoms.R198292
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34138.fqW@aWlaNjgi
ALYacTrojan.Inject.BDT
TACHYONBackdoor/W32.Agent.94208.GG
VBA32BScope.Trojan.Downloader
MalwarebytesBackdoor.Remcos
PandaTrj/Genetic.gen
ZonerTrojan.Win32.76707
ESET-NOD32Win32/Agent.RXL
TrendMicro-HouseCallBKDR_SOCMER.SM
RisingBackdoor.Remcos!1.B4AD (RDMK:cmRtazr2CqhqZZB79VFzH5HVXHyJ)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.RXL!tr
Ad-AwareTrojan.Inject.BDT
AVGWin32:RemcosRAT-A [Trj]
AvastWin32:RemcosRAT-A [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM07.1.E1BD.Malware.Gen

How to remove Backdoor:Win32/Rescoms?

Backdoor:Win32/Rescoms removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment