Trojan

How to remove “Trojan:Win32/Remcos.AG!MTB”?

Malware Removal

The Trojan:Win32/Remcos.AG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos.AG!MTB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Remcos.AG!MTB?


File Info:

crc32: 79768E9F
md5: 8536e6f28934c3fa1454b47650c9c96c
name: 8536E6F28934C3FA1454B47650C9C96C.mlw
sha1: b6a01c71de1f688cb91eddd6a4bbf5ad95d9bf5b
sha256: 398a8ad514fff3943f5cb05d7d2f3bf6a1c80b66ec7cfd824419863cb09c46cb
sha512: 0722a8836c3d6067bb1f29bc5f592ed78dadaf4a4da81bebc0d7ec2073b61605ac898887b82ab1bb150b6699afc122c54f5a9cdc65c0296b576038b6b29ed862
ssdeep: 12288:eh64bJetTqcMBttg2IJH7bRo4m9vSkN5cSpC47j:ecxjUgdJbbRo3UkN5vC47j
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan:Win32/Remcos.AG!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealBackdoor.Remcos
ALYacTrojan.GenericKD.46401172
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/GenKryptik.2f6ef186
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.28934c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FGBO
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyBackdoor.Win32.Remcos.tau
BitDefenderTrojan.GenericKD.46401172
MicroWorld-eScanTrojan.GenericKD.46401172
Ad-AwareTrojan.GenericKD.46401172
SophosGeneric ML PUA (PUA)
ComodoMalware@#3ljam5pccsdsk
BitDefenderThetaGen:NN.ZedlaF.34722.Eq4@aCXfSsh
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Vopak.hc
FireEyeGeneric.mg.8536e6f28934c3fa
EmsisoftTrojan.GenericKD.46401172 (B)
AviraTR/Kryptik.dwauf
KingsoftWin32.Hack.Remcos.t.(kcloud)
MicrosoftTrojan:Win32/Remcos.AG!MTB
ArcabitTrojan.Generic.D2C40694
AegisLabWorm.MSIL.Agent.o!c
GDataWin32.Backdoor.Remcos.B6Q1LQ
AhnLab-V3Trojan/Win.Generic.C4499884
McAfeeRDN/Generic.cf
MAXmalware (ai score=88)
VBA32Backdoor.Remcos
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0DF121
RisingTrojan.Kryptik!1.D6C7 (CLASSIC)
YandexTrojan.Slntscn24.bVVB1s
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.FFYV!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Remcos.AG!MTB?

Trojan:Win32/Remcos.AG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment