Backdoor

Backdoor:Win32/Remcos.WS!MTB removal

Malware Removal

The Backdoor:Win32/Remcos.WS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Remcos.WS!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates known Remcos directories and/or files
  • Creates known Remcos mutexes
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Remcos.WS!MTB?


File Info:

name: 68C5865D183F0BC4FD18.mlw
path: /opt/CAPEv2/storage/binaries/2daa8378ff5071359f9f4ccdf1070172199980f4b54505446aaba588e719a15c
crc32: 41F2CC2E
md5: 68c5865d183f0bc4fd1877b25553935f
sha1: edf4453d80ac0637c0336e36daf8fd066d0d8303
sha256: 2daa8378ff5071359f9f4ccdf1070172199980f4b54505446aaba588e719a15c
sha512: d3b989d0d73a1b3997f4f50bb3a31ffbeb51047d9b467ba01cb6316a74874ed62a8c025dcba26101111535b56feea9545bbde44c9228838c672c7e520c50fd77
ssdeep: 12288:bmi6B3J0uy3joDwgMb7sjXvgMX2cHACK3imyMrvrPIn14KupO6wzepO:D6hJjyzMhMb7sjX45CK3JPkurwze
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A71501266D1AA5D1C39489300D079B64EE197D33CFA1ED6F3AC03F6FE834A36615D628
sha3_384: fed8a1c09ba23863f0f904aa0876d0d75aebd6e5c271dab968db95f0a83070d8d90f42ba83145c79a869717fe7ec490c
ep_bytes: 688c834000e8eeffffff000000000000
timestamp: 2018-10-19 10:20:17

Version Info:

Translation: 0x0409 0x04b0
Comments: INTevation GmbH
FileDescription: INTevation GmbH
LegalCopyright: INTevation GmbH
LegalTrademarks: INTevation GmbH
ProductName: INTevation GmbH
FileVersion: 1.00
ProductVersion: 1.00
InternalName: syntheticism
OriginalFilename: syntheticism.exe

Backdoor:Win32/Remcos.WS!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKryjetor.tpNB
MicroWorld-eScanGen:Heur.PonyStealer.1m0@d0BnyBdi
FireEyeGeneric.mg.68c5865d183f0bc4
ALYacGen:Heur.PonyStealer.1m0@d0BnyBdi
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.PonyStealer.1m0@d0BnyBdi
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005483b31 )
AlibabaTrojan:Win32/VBKryjetor.a30fd469
K7GWTrojan ( 005483b31 )
Cybereasonmalicious.d80ac0
VirITTrojan.Win32.Dropper.CCT
CyrenW32/Injector.OV.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.EBGX
APEXMalicious
ClamAVWin.Malware.Ursu-6735652-0
KasperskyTrojan.Win32.VBKryjetor.bbyb
BitDefenderGen:Heur.PonyStealer.1m0@d0BnyBdi
NANO-AntivirusTrojan.Win32.Mlw.fjjclr
AvastWin32:VB-AJLQ [Trj]
RisingTrojan.Injector!1.B459 (CLASSIC)
EmsisoftGen:Heur.PonyStealer.1m0@d0BnyBdi (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.Siggen2.8271
ZillyaDropper.VBKryjetor.Win32.8
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionFareit-FMM!68C5865D183F
Trapminesuspicious.low.ml.score
SophosTroj/Agent-BBHK
IkarusTrojan.Win32.Injector
GDataGen:Heur.PonyStealer.1m0@d0BnyBdi
JiangminTrojan.VBKryjetor.isy
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=94)
Antiy-AVLTrojan/Win32.VBKryjetor
XcitiumTrojWare.Win32.Injector.EAZP@8fi00j
ArcabitTrojan.PonyStealer.EDC327
ZoneAlarmTrojan.Win32.VBKryjetor.bbyb
MicrosoftBackdoor:Win32/Remcos.WS!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP08.X1976
McAfeeFareit-FMM!68C5865D183F
TACHYONTrojan/W32.VB-VBKryjetor.876544.C
VBA32Trojan.VBKryjetor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
TencentMalware.Win32.Gencirc.10b132c2
YandexTrojan.GenAsa!SQIrhoxRIC0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73853783.susgen
FortinetW32/Injector.EAZP!tr
BitDefenderThetaGen:NN.ZevbaF.36662.1m0@a0BnyBdi
AVGWin32:VB-AJLQ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Remcos.WS!MTB?

Backdoor:Win32/Remcos.WS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment