The Backdoor:Win32/Remcos!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.
What Backdoor:Win32/Remcos!MTB virus can do?
z.whorecord.xyz |
a.tomx.xyz |
wzefi.duckdns.org |
File Info:
crc32: 10DD0345md5: a07b0a1e30a411eb7b2acff98a07312fname: upload_filesha1: 203a1af72a21fafcd06bd545c66a2d28318fdd89sha256: 7fa4e7e851fd8997ceb6a4b87912523dd682387f70eb840afc01806e08c26c2fsha512: c0f6a1b8da6944cf7b9d3fa68ee087d53114b586d7b050fcc4bcb8e9aa7533a40c77fc4bf2c90edb0d4bd0d0b757c6dc467e4355e80fe07df52d9d51657e23dcssdeep: 1536:10jP7/L1B5rVmN8sxHv2M28ix8EUaJxWZoB4u0OVE01+t:O1VmhaH8EFvW+0OVE0Qttype: PE32 executable (GUI) Intel 80386, for MS WindowsVersion Info:
LegalCopyright: x5f00x8feax8feax5f00x5f00x5f00x514bx5409x514bx8feax8feax8feax8feax7ef4x5409x5f00x8feax5f00x8feax5f00x5f00x5409x8feax5f00x514bx5f00x5f00x7ef4x5f00Assembly Version: 2.3.2.6FileVersion: 0.5.1.2CompanyName: x514bx7ef4x514bx7ef4x514bx8feax5409x7ef4x5f00x8feax7ef4x8feax5f00x7ef4x5f00x514bx5409x8feax514bx8feax8feax8feax5f00x8feax8feax5f00x5f00x5409LegalTrademarks: x8feax514bx7ef4x7ef4x5f00x7ef4x8feax7ef4x7ef4x5f00Comments: x5f00x8feax5f00x7ef4x5f00x8feax5f00x8feax8feax5f00ProductName: x5f00x7ef4x5f00x5f00x5409x8feax8feax8feax514bx514bx7ef4x514bx514bx8feax5409x5f00x8feax514bx514bx5409x5f00ProductVersion: 2.3.2.6FileDescription: x8feax7ef4x5409x8feax514bx5f00x514bx5f00x5409x5f00OriginalFilename: x5f00x7ef4x5f00x5f00x5409x8feax8feax8feax514bx514bx7ef4x514bx514bx8feax5409x5f00x8feax514bx514bx5409x5f00.exeTranslation: 0x0409 0x0514
Bkav | W32.AIDetectVM.malware1 |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Ser.Mikey.2127 |
CAT-QuickHeal | Trojan.IGENERIC |
McAfee | GenericRXLJ-HT!A07B0A1E30A4 |
Cylance | Unsafe |
VIPRE | Trojan.Win32.Generic!BT |
AegisLab | Trojan.Win32.Agentb.4!c |
Sangfor | Malware |
K7AntiVirus | Trojan ( 0019d9b81 ) |
BitDefender | Gen:Variant.Ser.Mikey.2127 |
K7GW | Trojan ( 0019d9b81 ) |
CrowdStrike | win/malicious_confidence_100% (W) |
Arcabit | Trojan.Ser.Mikey.D84F |
Invincea | Mal/Generic-R |
Cyren | W32/Antiav.INDT-0919 |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
Paloalto | generic.ml |
ClamAV | Win.Malware.AveMaria-8799014-1 |
Kaspersky | Trojan.Win32.Agentb.jiad |
Alibaba | Backdoor:Win32/Agentb.03d70930 |
NANO-Antivirus | Trojan.Win32.AntiAV.fljpfv |
Ad-Aware | Gen:Variant.Ser.Mikey.2127 |
Emsisoft | Gen:Variant.Ser.Mikey.2127 (B) |
Comodo | TrojWare.Win32.AntiAV.VA@81mmki |
F-Secure | Trojan.TR/Redcap.ghjpt |
DrWeb | Trojan.PWS.Maria.3 |
Zillya | Trojan.Agent.Win32.1391531 |
TrendMicro | TrojanSpy.Win32.MOCRT.SM |
McAfee-GW-Edition | BehavesLike.Win32.Dropper.cm |
FireEye | Generic.mg.a07b0a1e30a411eb |
Sophos | Troj/AntiAV-P |
SentinelOne | DFI – Malicious PE |
Jiangmin | Trojan.Agentb.eab |
Webroot | W32.Trojan.Gen |
Avira | TR/Redcap.ghjpt |
eGambit | Trojan.Generic |
MAX | malware (ai score=84) |
Antiy-AVL | Trojan/Win32.SGeneric |
Microsoft | Backdoor:Win32/Remcos!MTB |
ZoneAlarm | Trojan.Win32.Agentb.jiad |
GData | Win32.Backdoor.AveMaria.A |
Cynet | Malicious (score: 100) |
VBA32 | Trojan.Agentb |
ALYac | Gen:Variant.Ser.Mikey.2127 |
Malwarebytes | Backdoor.AveMaria |
ESET-NOD32 | a variant of Win32/Agent.TJS |
TrendMicro-HouseCall | TrojanSpy.Win32.MOCRT.SM |
Rising | Stealer.AveMaria!1.BA1C (CLASSIC) |
Yandex | Trojan.AntiAV!DUTgE8gwzUM |
Ikarus | Trojan.Win32.Agent |
Fortinet | W32/Agent.TJS!tr |
BitDefenderTheta | Gen:NN.ZexaF.34282.ky0@aq1I2rgi |
AVG | Win32:Malware-gen |
Avast | Win32:Malware-gen |
Qihoo-360 | Win32/Trojan.59e |
The Malware.AI.1865006162 is considered dangerous by lots of security experts. When this infection is active,…
The Trojan.Win32.Agent.xbnsym is considered dangerous by lots of security experts. When this infection is active,…
The Backdoor:Win32/AsyncRAT is considered dangerous by lots of security experts. When this infection is active,…
The Win32:VB-NPD [Wrm] is considered dangerous by lots of security experts. When this infection is…
The Symmi.4579 is considered dangerous by lots of security experts. When this infection is active,…
The Lazy.487114 is considered dangerous by lots of security experts. When this infection is active,…