Backdoor

Backdoor.Win32.Remcos.mgt removal instruction

Malware Removal

The Backdoor.Win32.Remcos.mgt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Remcos.mgt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Remcos.mgt?


File Info:

crc32: A41BDB99
md5: e1d5240f4604faa8fa2c43a8b0108015
name: soft.exe
sha1: aad98106231760b14eae9bdadcc3adaf883adefd
sha256: c4c207d17ef423efce9bc476b2f091e5aa2b904c8a032c8c4b9705fac96f6c4e
sha512: 706175a6f1c739a41140bb45385e4690c56c11aaa2c4947407756fb7663293e80489f888d07a2d4610f899314599da97b100b1e6d3bc7a987d5f46c615884cbf
ssdeep: 768:Sb8qQRTW7L0jc5VavvX3L10FOYYB26pY4Xm2Je5:e8bQngLiF+B2aY4Xm2JA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: KEJTHA
FileVersion: 1.00
ProductName: sprog
ProductVersion: 1.00
FileDescription: Her5
OriginalFilename: KEJTHA.exe

Backdoor.Win32.Remcos.mgt also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42687824
FireEyeGeneric.mg.e1d5240f4604faa8
Qihoo-360Trojan.Generic
McAfeeFareit-FRM!E1D5240F4604
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005615621 )
BitDefenderTrojan.GenericKD.42687824
K7GWTrojan ( 005615621 )
TrendMicroTROJ_GEN.R002C0PBR20
F-ProtW32/Kryptik.BCI.gen!Eldorado
SymantecInfostealer
APEXMalicious
ClamAVWin.Dropper.Fareit-7600597-0
GDataTrojan.GenericKD.42687824
KasperskyBackdoor.Win32.Remcos.mgt
AlibabaBackdoor:Win32/Remcos.38aec1f2
AegisLabTrojan.Multi.Generic.4!c
AvastWin32:Trojan-gen
RisingBackdoor.Remcos!8.B89E (CLOUD)
Ad-AwareTrojan.GenericKD.42687824
SophosMal/FareitVB-W
DrWebTrojan.PackedENT.133
Invinceaheuristic
McAfee-GW-EditionFareit-FRM!E1D5240F4604
EmsisoftTrojan.GenericKD.42687824 (B)
IkarusTrojan-Spy.FormBook
CyrenW32/Kryptik.BCI.gen!Eldorado
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D28B5D50
ZoneAlarmBackdoor.Win32.Remcos.mgt
MicrosoftTrojan:Win32/FormBook.T!MTB
ALYacTrojan.GenericKD.42687824
MalwarebytesTrojan.MalPack.VB
ESET-NOD32a variant of Win32/Injector.EKTH
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMTHD.hp
TencentWin32.Backdoor.Remcos.Akor
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_89%
FortinetW32/GenKryptik.EFHR!tr
BitDefenderThetaGen:NN.ZevbaCO.34096.dm0@ayjEqbai
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.75079713.susgen

How to remove Backdoor.Win32.Remcos.mgt?

Backdoor.Win32.Remcos.mgt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment