Backdoor

Backdoor:Win32/Remcos.AC!MTB removal instruction

Malware Removal

The Backdoor:Win32/Remcos.AC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Remcos.AC!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r4—sn-4g5e6nzz.gvt1.com

How to determine Backdoor:Win32/Remcos.AC!MTB?


File Info:

crc32: DE033A09
md5: bb94150e888bb29e23b648c588cc961a
name: cas.exe
sha1: 5bda137316b675f811021ea0867d210be6dd0d84
sha256: bc558167f567e473dbe00f744143dd32c05f50f8d85f2b822b89b0687bf00262
sha512: 4f79ba5003b01e0b77dcb5d0dc59673907e92772a96f42e3d21962fd73fc12281c4b5c883d4e83a92119446e072d6aa19d6508b8e81291f3d9b1405f527a77e7
ssdeep: 12288:CpsT2Ie2Bkt/kAb3J6X9nQuLcS90EoJHgquJl5Phin:Km+t/kAbQA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xc2xa9 1998 - 2019
Assembly Version: 8.1.9.9
InternalName: VQhnrIKkCZYZ.exe
FileVersion: 1.8.0.0
CompanyName: SoftCom
LegalTrademarks:
Comments: pfkjfgdgbdjsdkm
ProductName: Microsoft Office Suite Service Pack 2 Setup
ProductVersion: 1.8.0.0
FileDescription: ynfgfdjhddfkldfnmdf
OriginalFilename: VQhnrIKkCZYZ.exe

Backdoor:Win32/Remcos.AC!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.43075418
McAfeeFareit-FSX!BB94150E888B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00565c411 )
BitDefenderTrojan.GenericKD.43075418
K7GWTrojan ( 00565c411 )
Cybereasonmalicious.316b67
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataWin32.Backdoor.Remcos.3NVGZK
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
AegisLabTrojan.MSIL.NanoBot.m!c
RisingBackdoor.Remcos!8.B89E (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#t8kl4kxxvmbd
F-SecureTrojan.TR/AD.Remcos.feief
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.bb94150e888bb29e
EmsisoftTrojan.GenericKD.43075418 (B)
IkarusTrojan.MSIL.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.Remcos.feief
eGambitUnsafe.AI_Score_90%
MAXmalware (ai score=82)
MicrosoftBackdoor:Win32/Remcos.AC!MTB
ArcabitTrojan.Generic.D291475A
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
VBA32CIL.HeapOverride.Heur
Ad-AwareTrojan.GenericKD.43075418
MalwarebytesBackdoor.NanoCore
ESET-NOD32a variant of MSIL/Kryptik.VRL
TencentWin32.Backdoor.Remcos.Auto
FortinetMSIL/GenKryptik.EJNK!tr
BitDefenderThetaGen:NN.ZemsilF.34108.Em0@aCQDURm
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Backdoor.BO.5c9

How to remove Backdoor:Win32/Remcos.AC!MTB?

Backdoor:Win32/Remcos.AC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment