Trojan

Trojan:Win32/Remcos.RVAW!MTB (file analysis)

Malware Removal

The Trojan:Win32/Remcos.RVAW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos.RVAW!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Remcos.RVAW!MTB?


File Info:

name: 5D34846B89BF43502E2B.mlw
path: /opt/CAPEv2/storage/binaries/287a8c784bc439337cd063735d6941eb0a40f2a9137b085bb86dd8d4aa14fcc9
crc32: 6C5A99ED
md5: 5d34846b89bf43502e2be0d4fd004618
sha1: b0ff73e01fd0156facba2f9a4bf8cb319e1e3dd6
sha256: 287a8c784bc439337cd063735d6941eb0a40f2a9137b085bb86dd8d4aa14fcc9
sha512: 6207da1b9988f06fa0718bd105389b849ebf90e0d7f53ff624dd89f320a9fc920a0284123b1f742f56695ba517229a53360f4b40687ab1df27c6df933e13a8cf
ssdeep: 24576:ORTaL+A2f8Zhp8bYm1EnyWjkf0eFuPD+4m:gTaKsh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111456CE2A254DC72F06A3579CC89B2D0396B7CED6D3A5C8D166C394A1A73761392C03F
sha3_384: f66920621000747a0377b2f8fcab04d859e5bf043fdce59bd196084272e881a15fc1cff4f07eb5117a647e1a840e50fe
ep_bytes: 558bec83c4f0b860834800e8ccd2f7ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Remcos.RVAW!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Remcos.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Genie.198
FireEyeGeneric.mg.5d34846b89bf4350
SkyhighBehavesLike.Win32.Infected.th
McAfeeGenericRXAA-AA!5D34846B89BF
Cylanceunsafe
ZillyaBackdoor.Remcos.Win32.6645
SangforDownloader.Win32.Modiloader.Vsip
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan-Downloader ( 005a9dd21 )
K7AntiVirusTrojan-Downloader ( 005a9dd21 )
ArcabitTrojan.Genie.198
BitDefenderThetaGen:NN.ZelphiF.36744.lLW@amsC8Rpi
VirITTrojan.Win32.Genus.SYR
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.ModiLoader.VX
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderGen:Variant.Genie.198
NANO-AntivirusTrojan.Win32.Remcos.jzptaq
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf1fcc
TACHYONBackdoor/W32.DP-Remcos.1243648
EmsisoftGen:Variant.Genie.198 (B)
F-SecureHeuristic.HEUR/AGEN.1367917
DrWebTrojan.DownLoader46.2645
VIPREGen:Variant.Genie.198
TrendMicroTROJ_FRS.0NA103I723
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Remcos.dwe
WebrootW32.Malware.Gen
VaristW32/Trojan.EBVR-7686
AviraHEUR/AGEN.1367917
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Hack.Remcos.gen
XcitiumMalware@#mtxwadefwtyn
MicrosoftTrojan:Win32/Remcos.RVAW!MTB
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataGen:Variant.Genie.198
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.C5481925
VBA32BScope.Backdoor.Remcos
ALYacGen:Variant.Genie.198
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.DLF
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_FRS.0NA103I723
RisingDownloader.Agent!1.EFE4 (CLASSIC)
YandexTrojan.Igent.b0NC7E.4
IkarusTrojan.Agent
MaxSecureTrojan.Malware.9833444.susgen
FortinetW32/Injector.ESCX!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.01fd01
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Remcos.RVAW!MTB?

Trojan:Win32/Remcos.RVAW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment