Robocopy.exe is a legitimate process file popularly known as robocopy . It is associated with Microsoft Robocopy application, developed by Microsoft Corporation. It is located in C:\Windows\ by default.
Malware programmers write virus files with malicious scripts and save them as Robocopy.exe with an intention to spread virus on the internet.
Affected Platforms: Windows OS
How to determine if your computer is infected with Robocopy.exe malware?
Look out for the these symptoms to check if your PC is infected with Robocopy.exe malware:
- Internet connection is unstable
- Robocopy.exe occupies extra CPU space
- PC processing speed slows down
- Browser often redirects to irrelevant websites
- You get a lot of unsolicited ads and popups
- Computer screen freezes repeatedly
Take the following steps to diagnose your PC for possible Robocopy.exe malware attack:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside C:\Program Files, perform an an antivirus scan to get rid of the malware.
How to remove Robocopy.exe malware from system using Comodo Antivirus?
Step 1: Download the award-winning Free Comodo Antivirus.
Step 2: Select the “Do not detect new networks again” option when Comodo Internet Security internal firewall activates the network detection process.
Step 3: After network detection is over, click on the “Close” button for a scan window.
Step 4: Restart your PC.
Step 5: Wait for Comodo Internet Security to update the antivirus.
Step 6: Proceed with the quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be notified through an alert screen.
Step 8: Comodo Antivirus will remove Robocopy.exe malware from your computer including all other malwares!
| No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | N/A | Executable | a52e82c88235c1dd d7806f51f4ca24a5 9067173b |
5de6ff4b1ef9e39b a3034872633a5314 |
Win32.Neshta .A |
No | N/A | N/A | Turkey |
N/A |
- 4 items per page
- 8 items per page
- 16 items per page
- 32 items per page
| No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
|---|---|---|---|---|---|---|---|---|
| 1 | Microsoft | Executable | 7d8dfdb209621b5e 2700842fd301c74c 3a3896ad |
592be1ad0ed83c36 d5e68ca7a014a510 |
No | 5, 1, 1, 1010 |
XP010 | United States |
| 2 | Microsoft Corporation | Executable | 24845f3748344f50 e281f5eeb6d07778 8aa519a4 |
e8e10fa17ccae33d 8e646d6d939862eb |
No | 10.0.19041 .2075 (WinBuild. 160101.080 0) |
10.0.19041 .2075 |
Hungary |
| 3 | Microsoft Corporation | Executable | 1550a4b3e8d4e06d 4aa0ae3d901eeb88 aa80bc4f |
0a1aa3d138103ed9 fb645f6b02e41a2f |
No | 10.0.19041 .1741 (WinBuild. 160101.080 0) |
10.0.19041 .1741 |
United States |
| 4 | Microsoft Corporation | Executable | 58309d6fb390a492 46cb08831b20a2ee d02c9cb6 |
7c85e2886d756144 ec8765e9b1ff80c0 |
No | 10.0.22593 .1 (WinBuild. 160101.080 0) |
10.0.22593 .1 |
India |

Turkey
United States
Hungary
India
104.238.128.144/32
