Malware

GenPack:Generic.Remcos.3C1E1FF2 malicious file

Malware Removal

The GenPack:Generic.Remcos.3C1E1FF2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Generic.Remcos.3C1E1FF2 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
noraxvvx.linkpc.net

How to determine GenPack:Generic.Remcos.3C1E1FF2?


File Info:

crc32: 1BAA24A8
md5: 07d3634817f81efbc8bdd44d54810f2c
name: 07D3634817F81EFBC8BDD44D54810F2C.mlw
sha1: 8e480b288f96170abea206f85e36b969a700e7f1
sha256: e343f98bfc84149f4555b0716775cbec4c504a8af773d287035c871c6e74ee93
sha512: 3b9a40bb77cb03a73780006d5aa836af9d9e5c0dd1e476d12bdd7d08837d46c0b0f2290490a843d338acf08a928eb2386516cebb5c878a122aa6378a3ae3b57e
ssdeep: 6144:OQUq6YEOymCSI8uuBgT8JLLTO1m+/J1fsBKhoTFavEK+s+:OQU9YEOU7uBgYhWmOswia8K+7
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

GenPack:Generic.Remcos.3C1E1FF2 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.16786
CynetMalicious (score: 100)
ALYacGenPack:Generic.Remcos.3C1E1FF2
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.817f81
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rescoms.B
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Trojan.Remcos-9753190-0
KasperskyHEUR:Backdoor.Win32.Remcos.vho
BitDefenderGenPack:Generic.Remcos.3C1E1FF2
MicroWorld-eScanGenPack:Generic.Remcos.3C1E1FF2
Ad-AwareGenPack:Generic.Remcos.3C1E1FF2
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34236.nmqaaallMchi
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
FireEyeGeneric.mg.07d3634817f81efb
EmsisoftGenPack:Generic.Remcos.3C1E1FF2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hccqv
AviraHEUR/AGEN.1119280
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.34A967A
MicrosoftBackdoor:Win32/Remcos.GA!MTB
ArcabitGenPack:Generic.Remcos.3C1E1FF2
GDataGenPack:Generic.Remcos.3C1E1FF2
AhnLab-V3Malware/Win32.Generic.C4332433
McAfeeGenericRXPN-QB!A662C9CC5C34
MAXmalware (ai score=82)
VBA32Trojan.Inject
RisingBackdoor.Remcos!1.B6A7 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Rescoms.M!tr
AVGWin32:RATX-gen [Trj]

How to remove GenPack:Generic.Remcos.3C1E1FF2?

GenPack:Generic.Remcos.3C1E1FF2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment