Backdoor

Backdoor:Win32/Rescoms!pz information

Malware Removal

The Backdoor:Win32/Rescoms!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rescoms!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Rescoms!pz?


File Info:

name: 6578EA199450331EF062.mlw
path: /opt/CAPEv2/storage/binaries/16a04a7542d3f4624a51e1048b3fd3e5f0ee4cc87f3329cb8e0595c0e5bfadcf
crc32: 522207F4
md5: 6578ea199450331ef062ca47e504046d
sha1: eea920bd6b787d00f8aad88e8ee94a7aac2d8500
sha256: 16a04a7542d3f4624a51e1048b3fd3e5f0ee4cc87f3329cb8e0595c0e5bfadcf
sha512: 258edd0148382a27a2ca7b58b640a5ea67d7df5f4981fbf093f42269acb3cf528a180461012555cfdd1b48131734cd39ae700bebb5ff5aa9ccbaeaa8d5f5dc6c
ssdeep: 24576:XAHnh+eWsN3skA4RV1Hom2KXMmHaTS+Nrg5dbt5u:Kh+ZkldoPK8YaTlNUdu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B258C0273918036FFAF92735B65B20156BDA9291123C93F12B85DB9B9701F12E2D36F
sha3_384: 83febec9279aa244f654f03065ec79517905d0bff35de4eb602891f00615f2da0c846f91a108a18edd1c227bf1956e63
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-21 16:21:46

Version Info:

FileDescription: UserAccountControlSettings
OriginalFilename: acledit
CompanyName: CloudExperienceHostBroker
FileVersion: 204.924.610.214
LegalCopyright: WallpaperHost
ProductName: AppVScripting
ProductVersion: 171.617.816.278
Translation: 0x0409 0x04b0

Backdoor:Win32/Rescoms!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Script.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
SkyhighBehavesLike.Win32.Injector.dh
McAfeeArtemis!6578EA199450
Cylanceunsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Heur.AutoIT.16
BitDefenderThetaAI:Packer.0E292DA617
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.Autoit.DYR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Remcos-6986981-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderGen:Trojan.Heur.AutoIT.16
NANO-AntivirusTrojan.Win32.AutoIt.gbymui
AvastAutoIt:Injector-JF [Trj]
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
SophosMal/AuItInj-A
F-SecureHeuristic.HEUR/AGEN.1321294
DrWebTrojan.AutoIt.452
VIPREGen:Trojan.Heur.AutoIT.16
TrendMicroBackdoor.AutoIt.BLADABINDI.SMA.hp
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/AutoIt.JL.gen!Eldorado
AviraHEUR/AGEN.1321294
Antiy-AVLGrayWare/Win32.ShellCode.a
Kingsoftmalware.kb.a.995
MicrosoftBackdoor:Win32/Rescoms!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.AutoIT.16
GoogleDetected
AhnLab-V3Win-Trojan/AutoInj.Exp
VBA32Trojan-Downloader.Autoit.gen
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMA.hp
TencentWin32.Trojan.Generic.Mjgl
IkarusTrojan.Autoit
AVGAutoIt:Injector-JF [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Rescoms!pz?

Backdoor:Win32/Rescoms!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment