Malware

Emotet.128 (file analysis)

Malware Removal

The Emotet.128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Emotet.128 virus can do?

  • Authenticode signature is invalid

How to determine Emotet.128?


File Info:

name: 959453B9B44818A8A571.mlw
path: /opt/CAPEv2/storage/binaries/611420dc16ad5ae50b4695834897a590f65fe59a482e3d49519f8aa0216337f6
crc32: 3BAE76FC
md5: 959453b9b44818a8a57117b943c903e9
sha1: e4a5293951828c603a65fc410d6da65ebe5d93c1
sha256: 611420dc16ad5ae50b4695834897a590f65fe59a482e3d49519f8aa0216337f6
sha512: 807bdedf3ac61833430fc7062bf0c38e14d1d5291100003d753793f4ef8639398e62f02b048860a396c1d489d3e5a8a892398779130373b898a5909a2336831b
ssdeep: 3072:6PLr03ZSMqTk3DdGdk+8ZJ/K3l0mWKF8n4o8bnjRrNW:6zr3MqTSdR+8vSzjR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C148D1736E0C0F7D5A752314EF5EF79B2B6F9214F328A87A3900B0D1E32595893A762
sha3_384: cb58fd66a227340773272a9194e17a6d39a78fdfd4f0d7392462f645925bcf185ca2e8afed50cf829fbe59ba11d58223
ep_bytes: 558bec6aff6830484200686ccf400064
timestamp: 2006-04-20 21:59:21

Version Info:

CompanyName:
FileDescription: vchannel MFC Application
FileVersion: 1, 0, 0, 1
InternalName: vchannel
LegalCopyright: Copyright (C) 2005
LegalTrademarks:
OriginalFilename: vchannel.EXE
ProductName: vchannel Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Emotet.128 also known as:

LionicTrojan.Win32.Emotet.L!c
MicroWorld-eScanGen:Variant.Emotet.128
FireEyeGen:Variant.Emotet.128
SkyhighBehavesLike.Win32.BadFile.ch
McAfeeArtemis!959453B9B448
VIPREGen:Variant.Emotet.128
SangforSpyware.Win32.Emotet.Vw6q
BitDefenderGen:Variant.Emotet.128
EmsisoftGen:Variant.Emotet.128 (B)
VaristW32/ABRisk.HTXK-6670
Antiy-AVLTrojan/Win32.PossibleThreat
ArcabitTrojan.Emotet.128
GDataGen:Variant.Emotet.128
GoogleDetected
ALYacGen:Variant.Emotet.128
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09DO23
MaxSecureTrojan.Malware.209463362.susgen
FortinetW32/PossibleThreat

How to remove Emotet.128?

Emotet.128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment