Trojan

Trojan.Win32.Rekvex removal

Malware Removal

The Trojan.Win32.Rekvex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Rekvex virus can do?

  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Rekvex?


File Info:

name: ED31D7F934D49A6703EB.mlw
path: /opt/CAPEv2/storage/binaries/a80e3f09dc0932cf79156b7d759a523a6f00ece6c137dfbc2fdd6d018b30eb2a
crc32: 451D35EF
md5: ed31d7f934d49a6703eb7fd798ca3aff
sha1: 10629cb657cb00ab943e013bde2ed194982781e8
sha256: a80e3f09dc0932cf79156b7d759a523a6f00ece6c137dfbc2fdd6d018b30eb2a
sha512: 2b602ee78841f6cfd5ed3c63992694a6851e29036406d601c5e498f7fed2f6b5c138ce2c13392fdc94faf4f6739429f867f26fc65e38804a34b4ba2c4f498b82
ssdeep: 24576:/3vLRdVhZBK8NogWYO096OGi9J3YiWdCMJ5QxmjwC/hR:/3d5ZQ12xJIiW0MbQxA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A95D027B7518437D1332E7C4C3B9398546EBE201D39A44B7AEA1E4C9E782853D2E3D6
sha3_384: db62a800f65d5371ca71e879579d2744a6aab6a905b6d21ff8131d4c36a96c131d98cdb93cfd98c9b3e9f5bec0c147bc
ep_bytes: 558becb9080000006a006a004975f9b8
timestamp: 2021-12-11 12:45:48

Version Info:

CompanyName: 178网游工作室
FileDescription: 商业程序
InternalName: LoginTools.exe
LegalCopyright: 版权所有 (C) 2010
OriginalFilename: LoginTools.exe
ProductName: 商业程序
ProductVersion: 1, 0, 0, 0
FileVersion: 1,0,0,0
Translation: 0x0804 0x03a8

Trojan.Win32.Rekvex also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.16380
MicroWorld-eScanTrojan.Patched.SAP.Gen.2
CAT-QuickHealPUA.IgenericIH.S28654578
SkyhighBehavesLike.Win32.Sdbot.tm
McAfeeGenericRXGA-BH!ED31D7F934D4
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Patched.SAP.Gen.2
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 005439d61 )
K7GWRiskware ( 005439d61 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Patched.SAP.Gen.2
BitDefenderThetaAI:Packer.C6B1A80219
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.GameTool.S
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Bulz-9957991-0
KasperskyHEUR:Trojan.Win32.Rekvex.gen
BitDefenderTrojan.Patched.SAP.Gen.2
NANO-AntivirusTrojan.Win32.GameTool.jkptir
AvastWin32:Evo-gen [Trj]
TencentRiskware.Win32.Gametool.16000715
EmsisoftTrojan.Patched.SAP.Gen.2 (B)
F-SecureHeuristic.HEUR/AGEN.1324621
ZillyaTool.GameTool.Win32.1414
SophosGeneric ML PUA (PUA)
IkarusTrojan-Spy.Lmir
JiangminTrojan.Rekvex.ar
AviraHEUR/AGEN.1324621
Antiy-AVLRiskWare/Win32.GameTool
MicrosoftTrojan:Win32/Vindor!pz
ZoneAlarmHEUR:Trojan.Win32.Rekvex.gen
GDataWin32.Trojan.PSE.10SL7FA
GoogleDetected
AhnLab-V3Unwanted/Win32.GameHack.R355518
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
RisingMalware.Lmir!8.E96A (TFE:4:R81oTA2OgLH)
YandexRiskWare.GameTool!pAVj6IeTg+4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73832973.susgen
FortinetW32/Lmir.BQT!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.657cb0
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Rekvex?

Trojan.Win32.Rekvex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment