Backdoor

Backdoor:Win32/Remcos.ZK!MTB removal guide

Malware Removal

The Backdoor:Win32/Remcos.ZK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Remcos.ZK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Remcos.ZK!MTB?


File Info:

crc32: 927A55F1
md5: 86b820d9ea72c63b583eac542a2d2ac8
name: 86B820D9EA72C63B583EAC542A2D2AC8.mlw
sha1: 83f753b95746a64a39e265ba8be6d8ebc81d2ca2
sha256: 788510bf3fc20aacc76bd0ed1884ff8452f4e79023f2f3ad3072efbd7e74139d
sha512: d12d62c12160af70899542e4d0d3f4a1f474878a70729976270b5abe0ef598ee6e19093cec680dea0fd77d1b63946fdf7ec43d1a986db301e796e95c12e43016
ssdeep: 6144:zT4Dt6iVFI8ELPxyYri9hMic6wWHbUd9LJ3A58hQ1+v:zTSo8ELPcYkhMX6w6ed31Q1+v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Remcos.ZK!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.19590
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Wacapew
ALYacTrojan.GenericKD.45817996
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Remcos.53bfe2c2
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9ea72c
CyrenW32/Injector.AFF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EOSQ
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Agent.xahccu
BitDefenderTrojan.GenericKD.45817996
NANO-AntivirusTrojan.Win32.Inject.inqglf
MicroWorld-eScanTrojan.GenericKD.45817996
TencentWin32.Trojan.Agent.Ecaq
Ad-AwareTrojan.GenericKD.45817996
SophosMal/Generic-S
F-SecureTrojan.TR/Injector.bmkzc
BitDefenderThetaGen:NN.ZedlaF.34608.gq7@aOhhaJm
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R035C0DC521
McAfee-GW-EditionBehavesLike.Win32.Ipamor.fc
FireEyeGeneric.mg.86b820d9ea72c63b
EmsisoftTrojan.GenericKD.45817996 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dropper.Gen
MicrosoftBackdoor:Win32/Remcos.ZK!MTB
ArcabitTrojan.Generic.D2BB208C
AegisLabTrojan.Win32.Agent.4!c
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
GDataWin32.Trojan.Agent.A9MQ9M
McAfeeArtemis!86B820D9EA72
VBA32Trojan.Agent
MalwarebytesMalware.AI.2552383446
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R035C0DC521
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.Igent.bVrcUq.5
IkarusTrojan.Agent
FortinetW32/Injector.AFC!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HyoDn6YA

How to remove Backdoor:Win32/Remcos.ZK!MTB?

Backdoor:Win32/Remcos.ZK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment