Trojan

How to remove “Trojan:Win32/Remcos!pz”?

Malware Removal

The Trojan:Win32/Remcos!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remcos!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Remcos!pz?


File Info:

name: 4C80BF1230F4750FC9D5.mlw
path: /opt/CAPEv2/storage/binaries/a6a84fea7b9a35a807840be6d0e34e4d721be41234e4aae29d1c432b43c5f92d
crc32: B8DC0057
md5: 4c80bf1230f4750fc9d55f570f8a12bf
sha1: 7bacd1789d1fde1fb45dc855ab91d51f41863800
sha256: a6a84fea7b9a35a807840be6d0e34e4d721be41234e4aae29d1c432b43c5f92d
sha512: cb9474643bf9815461977d3908cdfff3bc68aa5b3d5ad58a50a43cc6b02a6b217990e2a29815894567b4662c51cade89fb83a7cd7f43c419ad92c8d95dcaadf4
ssdeep: 12288:HRXxReZj3WZfj/2eSseWFaIe2+f8CL47bs/ZfW:Hx7cyF2eSsewS8W47eZO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123A4AF02BAC1C072D57661300D26E776DEB8BC20193A457BB3DA1D5BFD70190B63ABB2
sha3_384: b5692610bcd832ade0d92fec23d1b04fd056048e04584e37669860b8c1594aa3642f6ee06d05d5734077542a02bc592f
ep_bytes: e849040000e98efeffff558bec81ec24
timestamp: 2023-05-30 16:00:37

Version Info:

0: [No Data]

Trojan:Win32/Remcos!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.BypassUAC.4!c
ElasticWindows.Trojan.Remcos
MicroWorld-eScanGeneric.Remcos.4462C78B
ClamAVWin.Trojan.Remcos-9841897-0
FireEyeGeneric.mg.4c80bf1230f4750f
CAT-QuickHealTrojan.GenericRI.S30973839
SkyhighBehavesLike.Win32.Remcos.gh
McAfeeRemcos-FDQO!4C80BF1230F4
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Remcos.4462C78B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053ac2c1 )
AlibabaBackdoor:Win32/Remcos.c854fc5c
K7GWTrojan ( 0053ac2c1 )
Cybereasonmalicious.89d1fd
ArcabitGeneric.Remcos.4462C78B
BaiduWin32.Trojan.Kryptik.awm
VirITTrojan.Win32.GenusT.DMHR
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rescoms.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderGeneric.Remcos.4462C78B
NANO-AntivirusTrojan.Win32.Remcos.jwpryz
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:RATX-gen [Trj]
TencentBackdoor.Win32.Remcos.hb
SophosMal/Remcos-B
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.Inject4.57973
ZillyaTrojan.Rescoms.Win32.1410
EmsisoftGeneric.Remcos.4462C78B (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Remcos.dvb
GoogleDetected
AviraBDS/Backdoor.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/Win32.Rescoms.b
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Remcos!pz
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataGeneric.Remcos.4462C78B
VaristW32/ABRisk.XWQS-1371
AhnLab-V3Trojan/Win.RemcosRAT.R555762
BitDefenderThetaGen:NN.ZexaF.36680.ECW@a02zK@hi
ALYacGeneric.Remcos.4462C78B
TACHYONBackdoor/W32.Agent.493056.J
VBA32Backdoor.Remcos
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.Remcos!1.BAC7 (CLASSIC)
YandexTrojan.Rescoms!Q4WmJt0K72Q
IkarusBackdoor.Remcos
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Remcos.A!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Remcos!pz?

Trojan:Win32/Remcos!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment