Backdoor

Backdoor:MSIL/Remcos.AQ!MTB (file analysis)

Malware Removal

The Backdoor:MSIL/Remcos.AQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Remcos.AQ!MTB virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine Backdoor:MSIL/Remcos.AQ!MTB?


File Info:

crc32: 3B366D01
md5: 262a1ed87aae9a2d67e4e8ee77af0472
name: upload_file
sha1: 8afd75e3ff43064d2cacc05cba27c5bc4cd90217
sha256: 4e8319b60657f5cf0267967a37408e78f37569dea6fe24db2ddb49bb58cb9a04
sha512: 88e234dbfe9c911cd7ef83544eee5795bb9690b5fa700131a1705391a0aae9c6e96b348f23c0094a7d15f39b90ff87d659f8889a8504683a7da32e32efa97438
ssdeep: 768:j9NtoMQXep+L/UW0mJ0O45pYxb8b0zlPPUdrnT4K5zEASUl+Uf2hF:Tto3511J0O45Yb8boPCT4K5zEASUUUf8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 x7ef4x513fx41f. All rights reserved.
Assembly Version: 8.8.1.6
FileVersion: 3.4.7.2
CompanyName: x7ef4x7ef4x42b
LegalTrademarks: x6770x6770x41f
Comments: x7ef4x513fx41f x6770x41fx65af
ProductName: x65afx513fx7ef4 x41fx41fx513f
ProductVersion: 8.8.1.6
FileDescription: x513fx513fx65af x41fx6770x65af
OriginalFilename: x65afx513fx7ef4 x41fx41fx513f.exe
Translation: 0x0409 0x0514

Backdoor:MSIL/Remcos.AQ!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44061640
McAfeeArtemis!262A1ED87AAE
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 00570ee91 )
BitDefenderTrojan.GenericKD.44061640
K7GWTrojan-Downloader ( 00570ee91 )
CrowdStrikewin/malicious_confidence_60% (W)
InvinceaMal/Generic-S
CyrenW32/Trojan.HLCL-2128
SymantecTrojan Horse
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Agensla.d543d4e9
ViRobotTrojan.Win32.Z.Wacatac.83680
Ad-AwareTrojan.GenericKD.44061640
EmsisoftTrojan.GenericKD.44061640 (B)
F-SecureTrojan.TR/Dropper.MSIL.avtmf
DrWebTrojan.DownloaderNET.94
McAfee-GW-EditionRDN/Generic Downloader.x
FireEyeGeneric.mg.262a1ed87aae9a2d
SophosMal/Generic-S
WebrootW32.Trojan.Dropper
AviraTR/Dropper.MSIL.avtmf
MAXmalware (ai score=86)
MicrosoftBackdoor:MSIL/Remcos.AQ!MTB
ArcabitTrojan.Generic.D2A053C8
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.44061640
ALYacTrojan.GenericKD.44061640
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.GWP
TencentMsil.Trojan-downloader.Agent.Hoyk
IkarusTrojan-Downloader.MSIL.Agent
FortinetMalicious_Behavior.SB
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
MaxSecureTrojan.Malware.74499699.susgen

How to remove Backdoor:MSIL/Remcos.AQ!MTB?

Backdoor:MSIL/Remcos.AQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment