Remcos.exe Trojan Heuristic Analysis

Trojan Heuristic
Updated on 2024-07-16 (1 month ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.182.174
DB Version:2024-07-16 23:00:20

Trojan.Heur!.022D6021

The "Heur" stands for "heuristic," which means we use a set of rules, algorithms, or behavioral analysis to detect potential threats that may not have a specific, known signature. It's a proactive approach to identifying suspicious behavior or code patterns that could indicate the presence of a Trojan or other malware. The file's behavior or characteristics triggered the heuristic analysis as potentially malicious. However, it doesn't necessarily confirm that the file is indeed a Trojan. It could be a false positive, where a legitimate program exhibits behavior that resembles malicious activity.

Fileremcos.exe
Checked2024-07-16 20:53:07
MD5ed1e424ea6f625968a334377e8ac629f
SHA1ad00cc58a59a3d5b78d6603a1d09378e5dbd1647
SHA2561e5375b400f68c422804703390489b2cf3968c2a8bccb0b5b3c55fe1d2e3c991
SHA5125119b6ac8c1becda5b59a4802fc96828d338ba2d2767e5521bc226bf04b6637c1925b0cc1b0cf560540b1399730f695c55de23665e59d0683eb07d32939b8094
Imphashe2c065b1c331512012c564526756d6f2
File Size10346496 bytes

Trojan.Heur!.022D6021 Removal

Trojan.Heur!.022D6021 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.022D6021 without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

CompanyNameBreaking-Security.net
FileDescriptionREMCOS Remote Control & Surveillance
FileVersion1.7.0.0
LegalCopyrightBreakingSecurity.net
LegalTrademarksBreakingSecurity.net
ProductNameREMCOS Remote Control & Surveillance Software
ProductVersion1.7
Translation0x0409 0x04e4

Portable Executable Info

5953ab2c0a7c4eefe639e8b1e46217dc
5694997f3cb20ed78e22def74be28a56
70ccb87171f0d8f0
Image Base:0x00400000
Entry Point:0x01a6a50d
Compilation:2017-01-05 21:27:41
Checksum:0x00000000 (Actual: 0x009ec359)
OS Version:5.0
PEiD:PE32 executable (GUI) Intel 80386, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:13
Imports: oleaut32, advapi32, user32, kernel32, gdi32, version, netapi32, ole32, comctl32, msvcrt, shell32, wininet, comdlg32, winspool, wsock32, winmm, WTSAPI32,
Exports: 3
Resources:7

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x002f2fe0 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.itext 0x002f4000 0x0000232c 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.data 0x002f7000 0x00009e58 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.bss 0x00301000 0x0001a340 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.idata 0x0031c000 0x00003fea 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.didata 0x00320000 0x00000a62 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.edata 0x00321000 0x0000009a 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.tls 0x00322000 0x0000004c 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.rdata 0x00323000 0x0000005d 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.viotto0 0x00324000 0x009b94f1 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.viotto1 0x00cde000 0x009970f0 0x00997200 7ccb1430412a2258647f7c62fb01f50b 8.00
.reloc 0x01676000 0x000000fc 0x00000200 ecc30d7338f226ff50b7e3fb7fcaa658 2.43
.rsrc 0x01677000 0x000466a2 0x00046800 2268230a30592cae29f5e161e10aebb5 3.02

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware