Backdoor

Should I remove “Backdoor:Win32/Remcos.RS!MTB”?

Malware Removal

The Backdoor:Win32/Remcos.RS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Remcos.RS!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
1drv.ws
apps.identrust.com
p8cy0a.db.files.1drv.com

How to determine Backdoor:Win32/Remcos.RS!MTB?


File Info:

crc32: EE0A5EF8
md5: 1982963b64d323f39033d40641437595
name: 1982963B64D323F39033D40641437595.mlw
sha1: 8dde953e501af236d8be98dbf6d683fda458ba38
sha256: 60119cfc3cd6b63295c163fad7ab43949d62d5ed6bb024cd3054a2c64e8339c7
sha512: 75481182ea78ca9e6ee9022db2e2cfb869419a779e37e149d8c70da3e3f8132dcffcb53a368311bd7dfbe13dab1ee2eae7846aefd361848a375f91d4f61e31b1
ssdeep: 12288:Ps3/7rrM09fj4J5ybH/dGesLNDH+XFaqFV681o:PsnreJ5alkV+8So
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Remcos.RS!MTB also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.36166868
FireEyeGeneric.mg.1982963b64d323f3
McAfeeFareit-FZO!1982963B64D3
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36166868
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e501af
BitDefenderThetaGen:NN.ZelphiF.34780.0GY@a8WXpipi
CyrenW32/Delf.XBPV-6499
SymantecTrojan Horse
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.DDC
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaTrojanDownloader:Win32/Remcos.5805deb4
ViRobotTrojan.Win32.Z.Agent.856336
TencentWin32.Trojan.Falsesign.Dzkc
Ad-AwareTrojan.GenericKD.36166868
SophosMal/Generic-S + Troj/Remcos-WS
ComodoMalware@#rmsum7ucip2e
F-SecureTrojan.TR/Dldr.Delf.cxjed
DrWebTrojan.DownLoader36.36176
TrendMicroBackdoor.Win32.ARTEMIS.USMANAI21
McAfee-GW-EditionFareit-FZO!1982963B64D3
EmsisoftTrojan-Downloader.Delf (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Dldr.Delf.cxjed
MAXmalware (ai score=99)
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Remcos.RS!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D227DCD4
AhnLab-V3Malware/Gen.RL_Reputation.R363635
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataTrojan.GenericKD.36166868
CynetMalicious (score: 90)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
PandaTrj/Agent.AJS
TrendMicro-HouseCallBackdoor.Win32.ARTEMIS.USMANAI21
RisingBackdoor.Remcos!1.D16E (CLASSIC)
YandexTrojan.Igent.bVbEBS.3
IkarusTrojan.Win32.Injector
FortinetW32/Generic.DDC!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Backdoor.a07

How to remove Backdoor:Win32/Remcos.RS!MTB?

Backdoor:Win32/Remcos.RS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment