Trojan

BScope.TrojanBanker.Emotet malicious file

Malware Removal

The BScope.TrojanBanker.Emotet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What BScope.TrojanBanker.Emotet virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine BScope.TrojanBanker.Emotet?


File Info:

crc32: 52E8173B
md5: f493c40337cda3a808ccc062314bab19
name: 6Ws49d5.exe
sha1: 3dc160bd5a5ea38493d2baaaf9a089b66352c05a
sha256: 66466c80412fcfd6725d318e07b269eb3236b266c1f88cb6fbb4abd9448f8b4f
sha512: 73c08f3a1b4ae3ee16fce4bcf18c41daaaa7563cc038ee80709d18d589f4e6ef624dae18c642fec6ace25c23442a8f4fd1cc0b51f63852411f7e2f20a7330e63
ssdeep: 6144:jbhBfnGzZLCQwtnjnxOUs8eiTBpaZR1VCZU4Ljfnb7HGesFrAzcjGIg/lLpN4MA:j2+VtOUmi9pA1VC3fvVTaDowym8c
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

BScope.TrojanBanker.Emotet also known as:

MicroWorld-eScanTrojan.GenericKD.42012671
FireEyeGeneric.mg.f493c40337cda3a8
McAfeeEmotet-FOL!F493C40337CD
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42012671
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
F-ProtW32/Kryptik.AQH.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42012671
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Emotet.70876191
RisingTrojan.Generic@ML.93 (RDML:bn6PTkNvKGRUSKJ2Ix8u/w)
Ad-AwareTrojan.GenericKD.42012671
SophosMal/EncPk-APC
F-SecureTrojan.TR/AD.Emotet.roaur
DrWebTrojan.DownLoader30.38842
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan-Banker.Emotet
CyrenW32/Kryptik.AQH.gen!Eldorado
WebrootW32.Malware.gen
AviraTR/AD.Emotet.roaur
MAXmalware (ai score=82)
Antiy-AVLTrojan[Banker]/Win32.Emotet
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2810FFF
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Emotet.SM!MSR
AhnLab-V3Malware/Win32.Generic.C3560827
BitDefenderThetaGen:NN.ZexaF.32250.TOX@aW9wnJe
ALYacTrojan.GenericKD.42011308
VBA32BScope.TrojanBanker.Emotet
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GYGC
TrendMicro-HouseCallTROJ_GEN.R04AC0DKE19
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.DXOD!tr
AVGWin32:Malware-gen
Cybereasonmalicious.d5a5ea
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM01.1.3335.Malware.Gen

How to remove BScope.TrojanBanker.Emotet?

BScope.TrojanBanker.Emotet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment