Malware

Generic.Remcos.478D58BA removal instruction

Malware Removal

The Generic.Remcos.478D58BA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Remcos.478D58BA virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Remcos.478D58BA?


File Info:

name: C1B0BF5A5CCF7E5C535C.mlw
path: /opt/CAPEv2/storage/binaries/cbe10cec6faf95c5fd0ce7c76c1fb75905e97bfffe719ddaea9c631a34531557
crc32: E7A5275D
md5: c1b0bf5a5ccf7e5c535cd5651ca0c11c
sha1: 87fe2ba216c4c23bc29ad23acbe48dbfa72980cc
sha256: cbe10cec6faf95c5fd0ce7c76c1fb75905e97bfffe719ddaea9c631a34531557
sha512: b4befa34a4f0202574231931097dcabef46f2bc44a85eb3475b220cd3dfaadaaf3b5a388fa607c5dbf393b1ab6beef084332c4e26300325f35fc0e81f6a74df9
ssdeep: 6144:ju/TwNrjB5ikgxx+bdPoWYnRmCgEVAWK9goN1dFv/xpM9rsAOZZpAXo4DO:ju7wNB5iedQ1RmPEVAWONjpcs/Zp7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EB49E01BAD1C072D97554300D36E776EAB8BD2028364A7BB3D61D5BFE30190B73A6B6
sha3_384: b8f49d1d00f7424ee6c5f64f2a8569022be7e25d658dfce0a84da30b71206d839c86089be4f065b5f548d1cc0b2c1501
ep_bytes: e895040000e98efeffff558bec81ec24
timestamp: 2023-08-20 18:03:14

Version Info:

0: [No Data]

Generic.Remcos.478D58BA also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoader46.2190
MicroWorld-eScanGeneric.Remcos.478D58BA
McAfeeRemcos-FDQO!C1B0BF5A5CCF
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Rescoms.Win32.1460
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053ac2c1 )
K7GWTrojan ( 0053ac2c1 )
Cybereasonmalicious.a5ccf7
BitDefenderThetaGen:NN.ZexaF.36662.ECW@am0GQpci
VirITTrojan.Win32.Genus.SWW
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Remcos
ESET-NOD32a variant of Win32/Rescoms.B
APEXMalicious
ClamAVWin.Trojan.Remcos-9841897-0
KasperskyVHO:Trojan.Win32.BypassUAC.gen
BitDefenderGeneric.Remcos.478D58BA
NANO-AntivirusTrojan.Win32.Remcos.jyxnai
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf1882
EmsisoftGeneric.Remcos.478D58BA (B)
F-SecureBackdoor.BDS/Backdoor.Gen
BaiduWin32.Trojan.Kryptik.awm
VIPREGeneric.Remcos.478D58BA
McAfee-GW-EditionBehavesLike.Win32.Remcos.gh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.c1b0bf5a5ccf7e5c
SophosMal/Emogen-Y
SentinelOneStatic AI – Malicious PE
GDataGeneric.Remcos.478D58BA
JiangminBackdoor.Remcos.dvx
GoogleDetected
AviraBDS/Backdoor.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan[Backdoor]/Win32.Rescoms.b
ArcabitGeneric.Remcos.478D58BA
MicrosoftBackdoor:Win32/Remcos.GA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RemcosRAT.R555762
VBA32BScope.Trojan.Wacatac
ALYacGeneric.Remcos.478D58BA
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Remcos!1.BAC7 (CLASSIC)
IkarusBackdoor.Remcos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Remcos.A!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Generic.Remcos.478D58BA?

Generic.Remcos.478D58BA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment