Trojan

Trojan:Win32/Remcos.RVF!MTB information

Malware Removal

The Trojan:Win32/Remcos.RVF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos.RVF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan:Win32/Remcos.RVF!MTB?


File Info:

name: FD466BE86B22CC2A3D48.mlw
path: /opt/CAPEv2/storage/binaries/b318e3e55ec5b730b80730794feed764b7e13197bc6fedaa67e369eca18af72d
crc32: F16B03D8
md5: fd466be86b22cc2a3d4854b50fb3745b
sha1: 9b18e0a8f50e5709ed078cdd63551099344ec374
sha256: b318e3e55ec5b730b80730794feed764b7e13197bc6fedaa67e369eca18af72d
sha512: 986c1d9022d243ca9256238c582318571640c0fa71794e6ee70163a6f84526a070c4b5c51b29ae07cf2dff92029cd8fc22fdb10e024a3fc93d52498d4b75f139
ssdeep: 12288:dl9MEv3h5SuZicJohUytz1zAHDHxRDetor04cUAVzQ6rW4sIy7vdFRcqz:naEZ5SuZicyXtz1QDH/DeZhvrlQ5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B25AE15B240E8B3C23B16B98D6BF7E854297F116A18DC853AE97D0D0EF8A60FC15397
sha3_384: 197ae46be3bf1c31def78018b72ef8a0fcb227bca3b7f10ca7318b5f21c8cb343056cc2b422fa7a3ac265596a20684ea
ep_bytes: 558bec83c4f053b838e34900e8e772f6
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/Remcos.RVF!MTB also known as:

LionicTrojan.Win32.Remcos.m!c
DrWebTrojan.DownLoader44.12076
MicroWorld-eScanGen:Variant.Zusy.409525
FireEyeGen:Variant.Zusy.409525
McAfeeGenericRXAA-AA!FD466BE86B22
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0058b35f1 )
K7AntiVirusTrojan ( 0058b35f1 )
CyrenW32/Injector.BIVU-2673
SymantecScr.MalPbs!gen1
ESET-NOD32Win32/TrojanDownloader.Delf.DIB
TrendMicro-HouseCallTROJ_GEN.R002C0WL721
KasperskyHEUR:Trojan.Win32.Inject.gen
BitDefenderGen:Variant.Zusy.409525
AvastWin32:InjectorX-gen [Trj]
TencentMalware.Win32.Gencirc.11db3781
Ad-AwareGen:Variant.Zusy.409525
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WL721
McAfee-GW-EditionBehavesLike.Win32.Infected.fh
EmsisoftGen:Variant.Zusy.409525 (B)
IkarusTrojan.Inject
GDataGen:Variant.Zusy.409525
JiangminBackdoor.Remcos.dhh
AviraTR/Injector.hjvdo
Antiy-AVLTrojan/Generic.ASMalwS.34E8C8F
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Remcos.RVF!MTB
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R456894
ALYacGen:Variant.Zusy.409525
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
APEXMalicious
YandexTrojan.Inject!h0DkrY4oYXc
MAXmalware (ai score=88)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EQQS!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan:Win32/Remcos.RVF!MTB?

Trojan:Win32/Remcos.RVF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment