Malware

How to remove “Win32/Remtasu.F”?

Malware Removal

The Win32/Remtasu.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Remtasu.F virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

solfoda.no-ip.org

How to determine Win32/Remtasu.F?


File Info:

crc32: ADA1D53F
md5: f0001b3c909039d7a06e7755a75ca830
name: F0001B3C909039D7A06E7755A75CA830.mlw
sha1: 8768c36f526602842f1dec9a22cae676a0745268
sha256: 2fb5b72fa0cdb805a480ac392b1091b55fe58f16c1fda5a535b3e9bb7f919e09
sha512: d61f7ba54e68f94f7e0e8e07f29e62bfc8a666c48ded92065caddee9bb28fce3d42313820b2e2fb19b7b5d1ce48d3aea925799e14f181881b8e6b511ce41c3b6
ssdeep: 1536:3lJeUdDL7WigzSuBDHLlDm8E5e6ySp3cmJokYk7jvezorfzygWrdDxo5kwMtKexE:vzdDH5e6ySp3cmJokYk7jWwwx0fbpzBD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
InternalName: stub
FileVersion: 1.00
CompanyName: Ro
ProductName: Proyecto1
ProductVersion: 1.00
OriginalFilename: stub.exe

Win32/Remtasu.F also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
ALYacTrojan.Ransom.GenericKD.43355701
MalwarebytesTrojan.Agent.Generic
ZillyaTrojan.Xtrat.Win32.133
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Xtrat.6cd98370
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c90903
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Remtasu.F
APEXMalicious
AvastWin32:VBCrypt-CUA [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Xtrat.fti
BitDefenderTrojan.Ransom.GenericKD.43355701
NANO-AntivirusTrojan.Win32.Xtrat.diuzuu
MicroWorld-eScanTrojan.Ransom.GenericKD.43355701
TencentMalware.Win32.Gencirc.114cd9df
Ad-AwareTrojan.Ransom.GenericKD.43355701
SophosML/PE-A
ComodoMalware@#3ttnj3z9xehps
BitDefenderThetaGen:NN.ZevbaF.34170.em3@amh0MsM
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.35CD14
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
FireEyeGeneric.mg.f0001b3c909039d7
EmsisoftTrojan.Ransom.GenericKD.43355701 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Xtrat.ci
WebrootW32.Injector.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7EE376
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Xtrat.A
GDataTrojan.Ransom.GenericKD.43355701
TACHYONTrojan/W32.VB-Xtrat.80066
McAfeeGenericATG-FAD!F0001B3C9090
MAXmalware (ai score=100)
VBA32Trojan.Xtrat
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SPNR.35CD14
YandexTrojan.Xtrat!d5cTo6s8mf4
IkarusBackdoor.Win32.Xtrat
FortinetW32/Filecoder_CTBLocker.A!tr
AVGWin32:VBCrypt-CUA [Trj]

How to remove Win32/Remtasu.F?

Win32/Remtasu.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment