Backdoor

Backdoor:MSIL/RemcosInjector!MTB removal tips

Malware Removal

The Backdoor:MSIL/RemcosInjector!MTB file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Backdoor:MSIL/RemcosInjector!MTB virus can do?

  • Suspicious activity

How to determine Backdoor:MSIL/RemcosInjector!MTB?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: ML.Attribute.HighConfidence

File Info:

Name: fixo.exe

Size: 1258496

Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

MD5: 79bd86c9c1fc451d5559e60869e7b8d4

SHA1: a00c8ed1c781e5bdd85da21c70a0271455c2f128

SH256: 5ed078848c38e4cac6f8e4297b5cbd2fe2107f86614f1e3ff775b1c439517987

Version Info:

[No Data]

Backdoor:MSIL/RemcosInjector!MTB also known as:

ALYacSpyware.AgentTesla
APEXMalicious
Acronissuspicious
Ad-AwareTrojan.GenericKD.32673975
AegisLabTrojan.MSIL.Agensla.i!c
AhnLab-V3Malware/Win32.RL_Generic.C3544239
Antiy-AVLTrojan[PSW]/MSIL.Agensla
ArcabitTrojan.Generic.D1F290B7
BitDefenderTrojan.GenericKD.32673975
BitDefenderThetaGen:NN.ZemsilF.32245.mnW@a4CxCAfi
CAT-QuickHealTrojanpws.Msil
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.1c781e
CylanceUnsafe
CyrenW32/Arrakis.HRAH-2214
DrWebTrojan.PWS.Siggen2.37910
ESET-NOD32a variant of MSIL/Kryptik.TNC
Endgamemalicious (high confidence)
FireEyeGeneric.mg.79bd86c9c1fc451d
FortinetMSIL/Kryptik.TNC!tr
GDataTrojan.GenericKD.32673975
IkarusTrojan.MSIL.Crypt
JiangminTrojan.PSW.MSIL.ltp
K7AntiVirusTrojan ( 0055abb51 )
K7GWTrojan ( 0055abb51 )
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
MAXmalware (ai score=81)
MalwarebytesSpyware.AgentTesla.MSIL
McAfeeGenericRXJA-LO!79BD86C9C1FC
McAfee-GW-EditionArtemis!Trojan
MicroWorld-eScanTrojan.GenericKD.32673975
MicrosoftBackdoor:MSIL/RemcosInjector!MTB
Paloaltogeneric.ml
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.PSW.374
RisingTrojan.GenKryptik!8.AA55 (TFE:D:k0f0TM0oPeO)
SentinelOneDFI – Suspicious PE
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
TrendMicroTROJ_GEN.R002C0WK319
TrendMicro-HouseCallTROJ_GEN.R002C0WK319
VIPRETrojan.Win32.Generic!BT
WebrootW32.Trojan.Gen
YandexTrojan.Kryptik!sY+bnSZ1fBE
ZillyaTrojan.Kryptik.Win32.1817361
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen

How to remove Backdoor:MSIL/RemcosInjector!MTB?

Backdoor:MSIL/RemcosInjector!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment