Trojan

Trojan:Win32/Remcos.KZ!MTB malicious file

Malware Removal

The Trojan:Win32/Remcos.KZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos.KZ!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Remcos.KZ!MTB?


File Info:

crc32: 92F41AAD
md5: 5a7933b367881486ea63370d7d15a7b7
name: 5A7933B367881486EA63370D7D15A7B7.mlw
sha1: db51c0be2bb3e75541c1771d7025717b6278bada
sha256: d0a5e2bc62a6c0824a291aff797e45fd2b791ad76fd930306f57096e923cecf3
sha512: 08853cea0bb8772ecbb1ae5bf3c353fa146b98bbe181312aec1ee7b1c019b5b5436f0576a6283caa22812662c53365db9ad1cdb78fef0e3ce3e30a22344b9e63
ssdeep: 12288:eOjBrNtLavTpfaQADqPVl7xfWFFyx8cntYqgbRnNSrJUuBqvv:e+5MB9ADIlWMx8cntYxPStUJvv
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan:Win32/Remcos.KZ!MTB also known as:

K7AntiVirusTrojan ( 0057cb8f1 )
DrWebTrojan.PWS.Stealer.30053
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.46320966
CylanceUnsafe
SangforBackdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/Androm.5eed2eeb
K7GWTrojan ( 0057cb8f1 )
CyrenW32/Ninjector.B!Camelot
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Androm.gen
BitDefenderTrojan.GenericKD.46320966
MicroWorld-eScanTrojan.GenericKD.46320966
Ad-AwareTrojan.GenericKD.46320966
SophosMal/Generic-S + Troj/Keylog-AOW
ComodoMalware@#3rctuwadlqnv
F-SecureTrojan.TR/AD.XetimaLogger.pzisa
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeTrojan.GenericKD.46320966
EmsisoftTrojan.GenericKD.46320966 (B)
AviraTR/AD.XetimaLogger.pzisa
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Remcos.KZ!MTB
ArcabitTrojan.Generic.D2C2CD46
AegisLabTrojan.Win32.Remcos.m!c
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataTrojan.GenericKD.46320966
AhnLab-V3Malware/Win.Generic.C4480671
McAfeeArtemis!5A7933B36788
MAXmalware (ai score=81)
VBA32BScope.Trojan-Dropper.Injector
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00EJ21
RisingTrojan.Injector/NSIS!1.D61F (CLASSIC)
IkarusTrojan.Win32.Injector
FortinetNSIS/Injector.EPJF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Remcos.KZ!MTB?

Trojan:Win32/Remcos.KZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment