Trojan

Trojan-Banker.Win32.Emotet.pef removal guide

Malware Removal

The Trojan-Banker.Win32.Emotet.pef file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Banker.Win32.Emotet.pef virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Emotet.pef?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Trojan.Autoruns.GenericKDS.42002421

File Info:

Name: 3ggs6hi_927444.exe

Size: 202412

Type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

MD5: ccf87e9b08d5c3007fb75a1fd795392e

SHA1: 50a6734cdc909444a4ef3e0aed43eb07da8a2b35

SH256: 4e9b93cc62dd66415547f03ab3a2f52f60428e1a87806e35a82c33da2f17e618

Version Info:

[No Data]

Trojan-Banker.Win32.Emotet.pef also known as:

ALYacTrojan.Agent.Emotet
APEXMalicious
AVGWin32:BankerX-gen [Trj]
Ad-AwareTrojan.Autoruns.GenericKDS.42002421
AegisLabTrojan.Win32.Generic.4!c
AhnLab-V3Trojan/Win32.Emotet.R298664
AlibabaTrojan:Win32/Skeeyah.5bdb558a
Antiy-AVLTrojan[Banker]/Win32.Emotet
ArcabitTrojan.Autoruns.GenericS.D280E7F5
AvastWin32:BankerX-gen [Trj]
AviraTR/AD.Emotet.ecpry
BitDefenderTrojan.Autoruns.GenericKDS.42002421
BitDefenderThetaGen:NN.ZexaF.32250.mOX@aOwWouc
CAT-QuickHealTrojan.Fuery
ComodoMalware@#2ad4kjwuv08m5
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.cdc909
CylanceUnsafe
CyrenW32/Emotet.AAU.gen!Eldorado
DrWebTrojan.DownLoader30.37418
ESET-NOD32a variant of Win32/Kryptik.GYEQ
Endgamemalicious (high confidence)
F-ProtW32/Emotet.AAU.gen!Eldorado
F-SecureTrojan.TR/AD.Emotet.ecpry
FireEyeGeneric.mg.ccf87e9b08d5c300
FortinetW32/TrickBot.CC!tr
GDataTrojan.Autoruns.GenericKDS.42002421
IkarusTrojan-Banker.Emotet
Invinceaheuristic
JiangminTrojan.Banker.Emotet.mee
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
MAXmalware (ai score=81)
MaxSecureTrojan.Malware.11417434.susgen
McAfeeEmotet-FOL!CCF87E9B08D5
McAfee-GW-EditionBehavesLike.Win32.Pykse.cc
MicroWorld-eScanTrojan.Autoruns.GenericKDS.42002421
MicrosoftTrojan:Win32/Skeeyah.A!MTB
NANO-AntivirusTrojan.Win32.GenKryptik.ggmrlt
Paloaltogeneric.ml
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.298
RisingTrojan.Emotet!1.BF04 (CLASSIC)
SentinelOneDFI – Suspicious PE
SophosMal/EncPk-APC
SymantecTrojan Horse
TrendMicroTROJ_GEN.R002C0DKA19
TrendMicro-HouseCallTROJ_GEN.R002C0DKA19
VBA32Trojan.Emotet
VIPRETrojan.Win32.Generic!BT
ViRobotTrojan.Win32.S.Emotet.202412
WebrootW32.Trojan.Gen
YandexTrojan.PWS.Emotet!
ZillyaTrojan.Emotet.Win32.18677
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.pef

How to remove Trojan-Banker.Win32.Emotet.pef?

Trojan-Banker.Win32.Emotet.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment