Backdoor

Remcos.Backdoor.Bot.DDS removal

Malware Removal

The Remcos.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Remcos.Backdoor.Bot.DDS virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Remcos malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Remcos.Backdoor.Bot.DDS?


File Info:

name: AE8F570FC2640034A7F5.mlw
path: /opt/CAPEv2/storage/binaries/8de82fa7acf0cd7b95516edaf00d248bb7bfd651ec92d94c42bfb913cf31a33b
crc32: 13F11125
md5: ae8f570fc2640034a7f57f7e4fac0a26
sha1: 172cd6918914c4fa099e7c5576603d9e2eb5cf94
sha256: 8de82fa7acf0cd7b95516edaf00d248bb7bfd651ec92d94c42bfb913cf31a33b
sha512: d3ccc94ffd519eefcc54c92497bf6812dd61a59228d3379d814e815d0ff4c17aaa56d80f42fb9698172b64a40f91ccf73b2e566d5c75fafcb47ed9a710d8e555
ssdeep: 6144:cuTjz+RBwBjaIntGXvN6lyEUTnoYEBln9C8yGB/6CcrzAO2vRXzhdcOaS:cuTjz+6j5tcNoUkhBln9C9GgAvNh6S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4949E11B981C432D17211700E29EB769ABCBD212A35497B63EA5D9BFE701C0F73A763
sha3_384: e4ea5ff2d566dd2de5fa65924e12a07222367fcdcdc9353e2c3f0bfe61232ff1dd7f83f8e19381f58c884e1fdb5beefa
ep_bytes: e89f040000e98efeffff558bec56ff75
timestamp: 2023-02-19 10:44:07

Version Info:

0: [No Data]

Remcos.Backdoor.Bot.DDS also known as:

CynetMalicious (score: 100)
ALYacDeepScan:Generic.Dacic.A9349469.A.0C25EB96
Cylanceunsafe
ZillyaTrojan.Rescoms.Win32.1273
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057919d1 )
K7GWTrojan ( 0057919d1 )
Cybereasonmalicious.fc2640
CyrenW32/Trojan.GCT.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Rescoms.N
APEXMalicious
ClamAVWin.Trojan.Remcos-9841897-0
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderDeepScan:Generic.Dacic.A9349469.A.0C25EB96
NANO-AntivirusTrojan.Win32.Rescoms.jusqxq
MicroWorld-eScanDeepScan:Generic.Dacic.A9349469.A.0C25EB96
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.10bdde1c
EmsisoftDeepScan:Generic.Dacic.A9349469.A.0C25EB96 (B)
F-SecureBackdoor.BDS/Backdoor.Gen
VIPREDeepScan:Generic.Dacic.A9349469.A.0C25EB96
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.ae8f570fc2640034
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Remcos.dtt
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Rescoms
MicrosoftTrojan:Win32/Remcos!MTB
ArcabitDeepScan:Generic.Dacic.A9349469.A.0C25EB96
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataDeepScan:Generic.Dacic.A9349469.A.0C25EB96
GoogleDetected
AhnLab-V3Trojan/Win.RemcosRAT.R541637
McAfeeGenericRXSQ-HG!AE8F570FC264
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
MalwarebytesRemcos.Backdoor.Bot.DDS
RisingBackdoor.Remcos!1.BAC7 (CLASSIC)
YandexTrojan.Rescoms!e+TCDhNSDZc
IkarusBackdoor.Remcos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Remcos.M!tr
BitDefenderThetaGen:NN.ZexaF.36308.ACW@aWdCEOai
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Remcos.Backdoor.Bot.DDS?

Remcos.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment