Malware

Should I remove “Dropped:Generic.Remcos.BF94D74E”?

Malware Removal

The Dropped:Generic.Remcos.BF94D74E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Remcos.BF94D74E virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Generic.Remcos.BF94D74E?


File Info:

crc32: E7315105
md5: 7450bd6d921c7bf48975f800312f5eb3
name: 7450BD6D921C7BF48975F800312F5EB3.mlw
sha1: ef8a6e6d2aff2e04110929f95e6b6b7ceff9cd37
sha256: 551b886b528af4929cc7daf4cf5f606924619014c7a2fd447d0e4cfc71dcd729
sha512: 8e534696f034f5a9aff11e6b74b0439ba263065dc35bc76c7cd3ef7324ad92aa838783971c0f558bec3fff62c6f47c965bfc93d2531c6e8021858a97bfbe86e7
ssdeep: 12288:gf+Ud9dFEvMNIWXLg4SPw5+rTmu/ZIz1Eb:pUdyvMNDU25+r6YZUe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Dropped:Generic.Remcos.BF94D74E also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053ac2c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.13815
ClamAVWin.Trojan.Remcos-9753190-0
ALYacDropped:Generic.Remcos.BF94D74E
MalwarebytesBackdoor.Remcos
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan ( 0053ac2c1 )
Cybereasonmalicious.d921c7
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Rescoms.B
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Generic
BitDefenderDropped:Generic.Remcos.BF94D74E
MicroWorld-eScanDropped:Generic.Remcos.BF94D74E
TencentMalware.Win32.Gencirc.11ce3569
Ad-AwareDropped:Generic.Remcos.BF94D74E
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.CCW@a0m!z!ei
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
FireEyeGeneric.mg.7450bd6d921c7bf4
EmsisoftDropped:Generic.Remcos.BF94D74E (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.haqvl
AviraHEUR/AGEN.1141389
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.349AD2F
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Remcos.GA!MTB
ArcabitGeneric.Remcos.BF94D74E
ZoneAlarmHEUR:Trojan.Win32.Invader
GDataWin32.Malware.Bucaspys.B
AhnLab-V3Trojan/Win.RemcosRAT.R418128
McAfeeTrojan-FTRG!7450BD6D921C
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Remcos
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R06FC0DIM21
RisingBackdoor.Remcos!1.B6A7 (CLASSIC)
YandexTrojan.Agent!b5RIlBBZTu8
IkarusTrojan.Win32.Rescoms
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rescoms.M!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Dropped:Generic.Remcos.BF94D74E?

Dropped:Generic.Remcos.BF94D74E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment