Trojan

Trojan:Win32/Remcos!pz (file analysis)

Malware Removal

The Trojan:Win32/Remcos!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Remcos malware family

How to determine Trojan:Win32/Remcos!pz?


File Info:

name: 79E7C3034F413ECCDADB.mlw
path: /opt/CAPEv2/storage/binaries/704d05133ac891b9bf141eb44f6da7af11a1f87c07761a2df7d94214a8cd8baa
crc32: 4AAF5235
md5: 79e7c3034f413eccdadb1e54d65a258e
sha1: 837938cf021380061e0cc188fb1db1f317d7404d
sha256: 704d05133ac891b9bf141eb44f6da7af11a1f87c07761a2df7d94214a8cd8baa
sha512: ee7fa7cd7e028246b81c6c5ad74c68229c282cbe0801241c4c009dc773594b8fcc936ad87585ccd92126cd46827f0e760201db711c660e9d429747d9804972d6
ssdeep: 6144:tCJBSkHyP4DivRrO+d3cyU6320ho4nbJAj0N91EU7ZUFbz68AO2RjXH7ScrI6B3:tCJB/RuFhU6ho0ej0N91HFAAR77pB3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158949E12B492C032C17212740E29FB7599BCBD212936497B73EA5E5BBE741C1BB36363
sha3_384: f49a6f1f1ae22d705665f8bab0548969f8e7c490135f6290d476c59402f81792ac54e4c8f769e3793c6a1f29f041e4e8
ep_bytes: e888040000e98efeffff558bec56ff75
timestamp: 2024-03-09 09:53:01

Version Info:

0: [No Data]

Trojan:Win32/Remcos!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanDeepScan:Generic.Dacic.A9349469.A.2BA284E5
CAT-QuickHealTrojan.RemcosRAT.S31331583
SkyhighBehavesLike.Win32.Remcos.gh
McAfeeGenericRXSQ-HG!79E7C3034F41
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Rescoms.Win32.1467
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057919d1 )
BitDefenderDeepScan:Generic.Dacic.A9349469.A.2BA284E5
K7GWTrojan ( 0057919d1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Genus.USH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Rescoms.N
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Trojan.Remcos-9841897-0
KasperskyHEUR:Backdoor.Win32.Remcos.gen
NANO-AntivirusTrojan.Win32.Remcos.jyxsuw
RisingBackdoor.Remcos!1.BAC7 (CLASSIC)
EmsisoftDeepScan:Generic.Dacic.A9349469.A.2BA284E5 (B)
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebBackDoor.Remcos.373
VIPREDeepScan:Generic.Dacic.A9349469.A.2BA284E5
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.79e7c3034f413ecc
SophosMal/Remcos-B
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Remcos.dvr
GoogleDetected
AviraBDS/Backdoor.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Rescoms.n
MicrosoftTrojan:Win32/Remcos!pz
ArcabitDeepScan:Generic.Dacic.A9349469.A.2BA284E5
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataWin32.Trojan.PSE.OZ2LF3
VaristW32/Trojan.GCT.gen!Eldorado
AhnLab-V3Trojan/Win.RemcosRAT.R604739
BitDefenderThetaGen:NN.ZexaF.36804.ACW@aS2Kv5li
ALYacDeepScan:Generic.Dacic.A9349469.A.2BA284E5
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/Genetic.gen
TencentBackdoor.Win32.Remcos.kc
YandexTrojan.Rescoms!PD6SbcKjrdw
IkarusBackdoor.Remcos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Remcos.M!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Remcos

How to remove Trojan:Win32/Remcos!pz?

Trojan:Win32/Remcos!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment