Trojan

About “Trojan:Win32/Remhead” infection

Malware Removal

The Trojan:Win32/Remhead is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Remhead virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Remhead?


File Info:

crc32: 0AF5142B
md5: 420b270bc6d2460155b1b5fff8b22f4d
name: 420B270BC6D2460155B1B5FFF8B22F4D.mlw
sha1: ebba49e56bc5776a8dcd9f3b4688007d3c0a9fa7
sha256: 15cd331abc1d7a7201f156be2163ae9acf9d7d78bbff540ccd5f01addffb3197
sha512: 113a2ed085a228d092cb298a09887c90bbb41ccaba60ed23b68586aadf6c4137d97ac83070f03c64ffd93b3d8ca2a83bc5ca25132e2174e007b73c7ba48c6880
ssdeep: 24576:syT46bMLV3GYFln34BqXsEWBpxA8TOJ4gXjANEAzn5pFdljzeyUYd/aTkBQTZvE:saAhGYznLSBf3OJD8n5pvMg/aTkBQTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
:
InternalName:
Description:
: r%x01FileDescription
:
LegalTrademarks:
Comments:
:
: r%x01FileDescription
FileVersion:
Translation: 0x0409 0x04b0

Trojan:Win32/Remhead also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.Dn0@dHlDF@pj
FireEyeGeneric.mg.420b270bc6d24601
McAfeeArtemis!420B270BC6D2
CylanceUnsafe
VIPREVirTool.Win32.VBInject.gen.dp (v)
AegisLabTrojan.Win32.VB.l4bq
SangforMalware
K7AntiVirusNetWorm ( 700000151 )
BitDefenderGen:Trojan.Heur.Dn0@dHlDF@pj
K7GWNetWorm ( 700000151 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/VBInject.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Trojan.Agent-733652
KasperskyTrojan.Win32.Agent.aibxu
NANO-AntivirusTrojan.Win32.Buzus.bkewri
TencentWin32.Trojan.Agent.Oyop
Ad-AwareGen:Trojan.Heur.Dn0@dHlDF@pj
EmsisoftGen:Trojan.Heur.Dn0@dHlDF@pj (B)
ComodoTrojWare.Win32.VBInject.IK@1qsu2f
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Inject.22654
ZillyaTrojan.Buzus.Win32.56606
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosML/PE-A + Mal/Nyrate-B
IkarusNet-Worm.Win32.Kolab
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Buzus
KingsoftWin32.Troj.Buzus.(kcloud)
MicrosoftTrojan:Win32/Remhead
ArcabitTrojan.Heur.E02E41
ZoneAlarmTrojan.Win32.Agent.aibxu
GDataGen:Trojan.Heur.Dn0@dHlDF@pj
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VBNA.R3814
Acronissuspicious
BitDefenderThetaAI:Packer.D11274141C
ALYacGen:Trojan.Heur.Dn0@dHlDF@pj
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
MalwarebytesMachineLearning/Anomalous.100%
PandaGeneric Malware
ESET-NOD32a variant of Win32/Injector.AWK
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.GenAsa!W3grhXhw9HQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Refroso.AGEA!tr
WebrootTrojan:Win32/Remhead
AVGFileRepMetagen [Malware]
Qihoo-360HEUR/QVM03.0.Malware.Gen

How to remove Trojan:Win32/Remhead?

Trojan:Win32/Remhead removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment