Malware

Mal/Generic-R + Troj/Emotet-CLM removal instruction

Malware Removal

The Mal/Generic-R + Troj/Emotet-CLM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Emotet-CLM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Mal/Generic-R + Troj/Emotet-CLM?


File Info:

crc32: FC998027
md5: 965eefd9363749c9b59f2c0e4bf4a996
name: 965EEFD9363749C9B59F2C0E4BF4A996.mlw
sha1: cbfd4ad95bc4330b677e64dd15db5cbb4784caf9
sha256: 5c65f15b05c5780592e1342f40ca46b146d3b5802a554cd8a86838053b4999cb
sha512: 3d89d78e5a1fba3dd77271e6c83c28edc9e250fe60f3be0fb685b2565c92ff6c9c169d1d65c019b6e81a64921580364778bb5e690851d357eb6f4fadd144aba0
ssdeep: 6144:XAzkZ1U0Y/Byyc3d3fk9rIFMoa7PmbW56:X+g1Apyyefk9rIFRM6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001
InternalName: TestMfc
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TestMfc Application
ProductVersion: 1, 0, 0, 1
FileDescription: TestMfc MFC Application
OriginalFilename: TestMfc.EXE
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/Emotet-CLM also known as:

BkavW32.ArdamaxNBJ.Trojan
K7AntiVirusTrojan ( 0056e06c1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.26135
CynetMalicious (score: 99)
CAT-QuickHealTrojan.EmotetPMF.S15506441
ALYacTrojan.Agent.Emotet
ZillyaTrojan.Emotet.Win32.24753
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056e06c1 )
Cybereasonmalicious.936374
CyrenW32/Emotet.AQN.gen!Eldorado
SymantecTrojan.Emotet
ESET-NOD32Win32/Emotet.CD
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Atraps-9427196-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.vho
BitDefenderTrojan.Agent.EVFG
NANO-AntivirusTrojan.Win32.Emotet.hrwbum
ViRobotTrojan.Win32.Emotet.307200.D
MicroWorld-eScanTrojan.Agent.EVFG
TencentMalware.Win32.Gencirc.10ce397c
Ad-AwareTrojan.Agent.EVFG
SophosMal/Generic-R + Troj/Emotet-CLM
F-SecureTrojan.TR/ATRAPS.Gen
McAfee-GW-EditionEmotet-FRV!965EEFD93637
FireEyeGeneric.mg.965eefd9363749c9
EmsisoftTrojan.Emotet (A)
JiangminBackdoor.Emotet.sg
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Banker]/Win32.Emotet
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Agent.EVFG
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.vho
GDataTrojan.Agent.EVFG
TACHYONBackdoor/W32.Emotet.307200.B
AhnLab-V3Trojan/Win32.Emotet.R348787
McAfeeEmotet-FRV!965EEFD93637
MAXmalware (ai score=83)
VBA32Trojan.Downloader
MalwarebytesTrojan.MalPack.TRE
RisingTrojan.Generic@ML.100 (RDML:pudwJEBgEwNpHK497oLCQg)
YandexTrojan.Emotet!vEaZ2x/SUQE
IkarusTrojan-Banker.Emotet
MaxSecureTrojan.Malware.105704544.susgen
FortinetW32/Kryptik.HFMI!tr
AVGWin32:Trojan-gen

How to remove Mal/Generic-R + Troj/Emotet-CLM?

Mal/Generic-R + Troj/Emotet-CLM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment