Trojan

Trojan-Banker.Win32.Emotet.gbko removal tips

Malware Removal

The Trojan-Banker.Win32.Emotet.gbko is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gbko virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)

How to determine Trojan-Banker.Win32.Emotet.gbko?


File Info:

crc32: D656C135
md5: b78099684daf74091887d8d0cdbd8779
name: upload_file
sha1: ab164f408294da6a18db62241bb3ba17bbf5a5f4
sha256: 0a2c526c9ab537029ca9cff864ce2c4710785de8a20ca697f83d73c606adddfb
sha512: b9ac8742362fa19464599d958595908400291cd336cf99a92de2d1a75b013f3f1fe81722d43af8ae35a9e6d8f49c25fb87246e75814deda516f5e89d969c36aa
ssdeep: 12288:Kk7/FTNhj7jMshXLdSi2usAXPmv9Xo5+jO:dksdLdP2LX7O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Emotet.gbko also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69511
FireEyeTrojan.GenericKDZ.69511
McAfeeEmotet-FRV!B78099684DAF
BitDefenderTrojan.GenericKDZ.69511
K7GWTrojan ( 005600261 )
CyrenW32/Emotet.YRNT-5026
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Banker.Win32.Emotet.gbko
Ad-AwareTrojan.GenericKDZ.69511
DrWebTrojan.DownLoader34.24759
SophosTroj/Emotet-CLF
F-ProtW32/Emotet.APJ
FortinetW32/Emotet.AJQ!tr
ArcabitTrojan.Generic.D10F87
ZoneAlarmTrojan-Banker.Win32.Emotet.gbko
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32Win32/Emotet.CD
MAXmalware (ai score=87)
GDataWin32.Trojan.PSE.126CQ22
Qihoo-360Generic/HEUR/QVM41.2.4E50.Malware.Gen

How to remove Trojan-Banker.Win32.Emotet.gbko?

Trojan-Banker.Win32.Emotet.gbko removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment