Trojan

Trojan:MSIL/Remcos.EO!MTB removal instruction

Malware Removal

The Trojan:MSIL/Remcos.EO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Remcos.EO!MTB virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/Remcos.EO!MTB?


File Info:

crc32: 27E74441
md5: 7c56b212efbee6f8395051ee896d9d50
name: 7C56B212EFBEE6F8395051EE896D9D50.mlw
sha1: 3ab8efe3a467b01885a564a5ba60bc52142ee935
sha256: b2007a0e1e70eec1de0bc169055b1a3d87b96a24d47fb1e3332b9a56606e43f0
sha512: faaaefca053641dfdee257abecd290bdc3fbac181cbb3ed503f19125fac10444e658b6f934e339a3a8b8f31c42bd7d7e3cee4813abad1d13b9f836c56c6d8083
ssdeep: 3072:OUQrTIF0nMpi6B32GhNvT0ybmIhYzZFsVlF7XEgC:Hx2GhNjkzZFsVlF7XE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: WindowsFormsApplication1.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: WindowsFormsApplication1
ProductVersion: 1.0.0.0
FileDescription: WindowsFormsApplication1
OriginalFilename: WindowsFormsApplication1.exe

Trojan:MSIL/Remcos.EO!MTB also known as:

K7AntiVirusTrojan ( 005723e91 )
LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37037564
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.91997
SangforBackdoor.MSIL.Bladabindi.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Remcos.9d744c1e
K7GWTrojan ( 005723e91 )
CyrenW32/MSIL_Kryptik.EMA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.ETQB
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderTrojan.GenericKD.37037564
NANO-AntivirusTrojan.Win32.Bladabindi.iwikut
MicroWorld-eScanTrojan.GenericKD.37037564
TencentMsil.Backdoor.Bladabindi.Ajby
Ad-AwareTrojan.GenericKD.37037564
SophosMal/Generic-S
ComodoMalware@#15pea86kqj0j2
BitDefenderThetaGen:NN.ZemsilF.34236.km0@aeqsBim
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WFA21
McAfee-GW-EditionGenericRXOU-WG!7C56B212EFBE
FireEyeGeneric.mg.7c56b212efbee6f8
EmsisoftTrojan.GenericKD.37037564 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.ercq
AviraHEUR/AGEN.1140191
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3357588
MicrosoftTrojan:MSIL/Remcos.EO!MTB
ArcabitTrojan.Generic.D23525FC
GDataTrojan.GenericKD.37037564
AhnLab-V3Malware/Win.Generic.C4513172
McAfeeGenericRXOU-WG!7C56B212EFBE
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WFA21
YandexTrojan.GenKryptik!kmfLr8hx/iA
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.73686729.susgen
FortinetMSIL/GenKryptik.ETMY!tr
AVGWin32:RATX-gen [Trj]

How to remove Trojan:MSIL/Remcos.EO!MTB?

Trojan:MSIL/Remcos.EO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment