Trojan

Trojan:Win32/Remcos.AL!MTB malicious file

Malware Removal

The Trojan:Win32/Remcos.AL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos.AL!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Remcos.AL!MTB?


File Info:

crc32: B41A4C5D
md5: 121bea217c0f5e700514e7354b6dfceb
name: 121BEA217C0F5E700514E7354B6DFCEB.mlw
sha1: 6e6a7ed2f5b2301a74d67c94d67ae84cb1bcd91a
sha256: c400fa0429a3b241dd2757ce322082c15786c3bb18eb71fe2ef3a1eb60c7e0d8
sha512: 321ea66a6c33e8b9c40d9a8e8f1354f93e27487189244a8f17ff06dbbc5933111f6d759a829d246b868582fa94a6f77a177a3be0e3113837ddd11f54124208fe
ssdeep: 24576:RYUkRHVFnyXv1qhqJ7ANT8QNE1C5h7bmhNK:RY9b0Uhq7hc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Remcos.AL!MTB also known as:

BkavW32.AIDetectGBM.malware.02
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36383989
McAfeeFareit-FZO!121BEA217C0F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577f611 )
BitDefenderTrojan.GenericKD.36383989
Cybereasonmalicious.2f5b23
CyrenW32/Injector.MSEU-4221
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Gorgon.gen
AlibabaTrojan:Win32/Injector.b742fa74
TencentWin32.Trojan.Falsesign.Ducp
Ad-AwareTrojan.GenericKD.36383989
SophosMal/Generic-S
DrWebTrojan.DownLoader36.42654
TrendMicroTROJ_FRS.0NA103BM21
McAfee-GW-EditionFareit-FZO!121BEA217C0F
FireEyeGeneric.mg.121bea217c0f5e70
EmsisoftTrojan.GenericKD.36383989 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.36383989
MAXmalware (ai score=80)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D22B2CF5
ZoneAlarmHEUR:Trojan.Win32.Gorgon.gen
MicrosoftTrojan:Win32/Remcos.AL!MTB
CynetMalicious (score: 100)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.4078401189
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EOOG
TrendMicro-HouseCallTROJ_FRS.0NA103BM21
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.Inject
eGambitPE.Heur.InvalidSig
FortinetW32/Delf.DCB!tr
BitDefenderThetaGen:NN.ZelphiF.34574.2GX@aCmmi@ii
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Gorgon.HwUBdcoA

How to remove Trojan:Win32/Remcos.AL!MTB?

Trojan:Win32/Remcos.AL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment