Trojan

How to remove “Trojan:Win32/Remcos.ZI!MTB”?

Malware Removal

The Trojan:Win32/Remcos.ZI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos.ZI!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Remcos.ZI!MTB?


File Info:

crc32: 1E887044
md5: c3c4fbf8aefbd9215f116ce6c429b882
name: C3C4FBF8AEFBD9215F116CE6C429B882.mlw
sha1: 5fff78a6a316da25aaae8c3b1755370b90e5361f
sha256: 4a74ac9210751c192d84ad49d567de4cc5f7d005f62767b59a6a7901051a5304
sha512: c5f3798b59969c932972fe39a9cd559569bf51c667d2772e3076cc5d58f20e9d3eba069f9d21106a9a5fade4a5dd9fde9f6d146ad174dbfb8263807f4a72f780
ssdeep: 12288:6SI98JWgTynjjFRUbkaWw+S9SmxgfPvMh4KdriR3BhOu75Jf2ydBrRJN7NNNNNNs:6Sgnn/USvf3BhOu75/PBp9Buz155
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Remcos.ZI!MTB also known as:

Elasticmalicious (high confidence)
McAfeeFareit-FZO!C3C4FBF8AEFB
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005785e41 )
K7GWTrojan ( 005785e41 )
CyrenW32/DelfInject.DR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Delf.DEM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Bingoml.gen
AlibabaTrojan:Win32/Fareit.c7db7c02
RisingTrojan.Injector!8.C4 (C64:YzY0Ok4yhv6d+6ZJ)
SophosGeneric ML PUA (PUA)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.DownLoader36.50028
McAfee-GW-EditionFareit-FZO!C3C4FBF8AEFB
FireEyeGeneric.mg.c3c4fbf8aefbd921
IkarusTrojan.Inject
AviraADWARE/Adware.Gen
MicrosoftTrojan:Win32/Remcos.ZI!MTB
ZoneAlarmHEUR:Trojan.Win32.Bingoml.gen
CynetMalicious (score: 100)
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.Injector
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/GenKryptik.DPIE!tr
BitDefenderThetaGen:NN.ZelphiF.34590.3GX@a0CUTOji
AVGWin32:Trojan-gen
Cybereasonmalicious.6a316d
AvastWin32:Trojan-gen

How to remove Trojan:Win32/Remcos.ZI!MTB?

Trojan:Win32/Remcos.ZI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment