Malware

About “Generic.Remcos.231D89CD (B)” infection

Malware Removal

The Generic.Remcos.231D89CD (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Remcos.231D89CD (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Generic.Remcos.231D89CD (B)?


File Info:

crc32: E32A6747
md5: aba2fe65ec6b88d673aba36e8ede66fd
name: ABA2FE65EC6B88D673ABA36E8EDE66FD.mlw
sha1: 29246068b88a03cdaeaa60ddb66695771671c0cf
sha256: e805927181cab5fe0702c15f83f89f6a299e52aeb97f2d7faeb73d0e8e04f1f6
sha512: d47ddd6a15b0b9b77cbee4f4b383ec366b341e2b602d95db6d1c2c07e0e546e9140a0f4d9297fb472d75afe487498d48d6042a40f6547c21074acc86a9314d3d
ssdeep: 49152:EfRepMDqWLQV6fIz0Yxoh/xijir23yzBuPM:E0pa3LQsf5Bh/xsiyCtuPM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Remcos.231D89CD (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Remcos.231D89CD
FireEyeGeneric.mg.aba2fe65ec6b88d6
Qihoo-360HEUR/QVM19.1.44A7.Malware.Gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0040f4ef1 )
BitDefenderDeepScan:Generic.Remcos.231D89CD
K7GWTrojan ( 0040f4ef1 )
Cybereasonmalicious.5ec6b8
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareDeepScan:Generic.Remcos.231D89CD
F-SecureTrojan.TR/Crypt.TPM.Gen
DrWebTrojan.DownLoader35.18438
InvinceaGeneric ML PUA (PUA)
EmsisoftDeepScan:Generic.Remcos.231D89CD (B)
AviraTR/Crypt.TPM.Gen
MicrosoftTrojan:Win32/Wacatac.DE!ml
GridinsoftTrojan.Win32.Packed.oa!s1
ArcabitDeepScan:Generic.Remcos.231D89CD
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Remcos.231D89CD
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.D33B6E8821
ALYacDeepScan:Generic.Remcos.231D89CD
MAXmalware (ai score=85)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack.Themida.Generic
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.Themida.HEK
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Remcos.231D89CD (B)?

Generic.Remcos.231D89CD (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment