Malware

Generic.Remcos.5049727C information

Malware Removal

The Generic.Remcos.5049727C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Remcos.5049727C virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
forclients.duckdns.org

How to determine Generic.Remcos.5049727C?


File Info:

crc32: 118BA6FD
md5: 2c33b961ff39e94ea3c877448dd6dc4a
name: i.exe
sha1: 20b77004f2c0b50a5aa3e93a210c5b9dd6edbcf4
sha256: 0cce530f17b7a4d84d468dcd348f75f153533d50844a13a92da1df27944385de
sha512: 331078574f5ed2c5eefbf87ed15bb831232d6f212f3d7f00f55cfbdcd0236a8e06239a9963b4230273aaecdfd6b881d895e58cf436dbf58e4fe41bae9d7d5f7e
ssdeep: 3072:mlh1qaSs6IF9OK4b80S2Van4Va1cpcQjed5OzqhUsa:Ch1qn3IF9Obbj/a1cpcQjeHOzqhUs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Remcos.5049727C also known as:

BkavW32.RanumbotGV.Trojan
DrWebTrojan.Siggen8.46567
MicroWorld-eScanGeneric.Remcos.5049727C
CAT-QuickHealTrojan.GenericRI.S8505068
ALYacGeneric.Remcos.5049727C
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0053ac2c1 )
BitDefenderGeneric.Remcos.5049727C
K7GWTrojan ( 0053ac2c1 )
Cybereasonmalicious.1ff39e
TrendMicroBKDR_SOCMER.SM
BitDefenderThetaGen:NN.ZexaF.34132.huW@aye6hbii
CyrenW32/Rescoms.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RemcosRAT-A [Trj]
ClamAVWin.Malware.Rescoms-6598304-0
GDataWin32.Malware.Bucaspys.B
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Remcos.hjssgb
ViRobotBackdoor.Win32.Remcos.266212
RisingBackdoor.Remcos!1.B6A7 (CLOUD)
Endgamemalicious (high confidence)
SophosTroj/Remcos-DI
ComodoTrojWare.Win32.Rescoms.B@7ijo3m
F-SecureBackdoor.BDS/Backdoor.Gen
ZillyaTrojan.Rescoms.Win32.115
Invinceaheuristic
MaxSecureTrojan.Malware.7164915.susgen
FireEyeGeneric.mg.2c33b961ff39e94e
EmsisoftGeneric.Remcos.5049727C (B)
IkarusBackdoor.Remcos
F-ProtW32/Rescoms.J.gen!Eldorado
JiangminTrojan.Generic.ebzsp
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/Win32.Rescoms
MicrosoftBackdoor:Win32/Rescoms.C!bit
ArcabitGeneric.Remcos.D4D0D7FC
SUPERAntiSpywareBackdoor.Rescoms/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Remcos.R291256
Acronissuspicious
McAfeeGenericRXGN-WO!2C33B961FF39
TACHYONBackdoor/W32.Remcos.126976.B
VBA32BScope.Backdoor.Rescoms
MalwarebytesBackdoor.Remcos
PandaTrj/Genetic.gen
ESET-NOD32Win32/Rescoms.B
TrendMicro-HouseCallBKDR_SOCMER.SM
TencentMalware.Win32.Gencirc.10b77a0b
YandexTrojan.Agent!C1EU+49IHto
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Rescoms.B!tr
Ad-AwareGeneric.Remcos.5049727C
AVGWin32:RemcosRAT-A [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM07.1.84FF.Malware.Gen

How to remove Generic.Remcos.5049727C?

Generic.Remcos.5049727C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment