Malware

How to remove “Troj/Emotet-CLF”?

Malware Removal

The Troj/Emotet-CLF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CLF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Emotet-CLF?


File Info:

crc32: 8093FE04
md5: 10913886183050182cf1868f91940b78
name: PglYw0WD1OK98jYeNU.exe
sha1: 064169c00bb0e0f47e9f6940792a8510e2f7a331
sha256: 12b5989bcfe64b340aaf7d5c3732cb0cd69b5848cd292bbe8837435c7ad84314
sha512: 22ca560803e2e7664bc3d54b1bdb4ff5636162092ca853cfc5b391faceaa690c426a972ca055bbfe1e0048f20fd65346fb57bc5e7740fad1e5b29d94f22df42b
ssdeep: 1536:9TzVpjvSoidl5SYuO7aaAMWVpuBb2v1RI/OZPv8qzrV:NjfiGGaaDVU1RIMvP5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004
InternalName: BrowseCtrlDemo
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: BrowseCtrlDemo Application
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: BrowseCtrlDemo MFC Application
OriginalFilename: BrowseCtrlDemo.EXE
Translation: 0x0409 0x04b0

Troj/Emotet-CLF also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Zusy.311462
FireEyeGen:Variant.Zusy.311462
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FRV!109138861830
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Zusy.311462
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0DHI20
F-ProtW32/Emotet.APY.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.cjdr
AlibabaTrojan:Win32/Emotet.7854a3c7
Ad-AwareGen:Variant.Zusy.311462
F-SecureTrojan.TR/Emotet.cjfjl
DrWebTrojan.DownLoader34.25065
FortinetPossibleThreat.MU
SophosTroj/Emotet-CLF
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.APY.gen!Eldorado
AviraTR/Emotet.cjfjl
MAXmalware (ai score=83)
ZoneAlarmBackdoor.Win32.Emotet.cjdr
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R348099
VBA32Trojan.Downloader
ALYacGen:Variant.Zusy.311462
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R002C0DHI20
RisingTrojan.Kryptik!1.CAD0 (CLASSIC)
GDataWin32.Trojan.PSE.1Y6ESJV
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Troj/Emotet-CLF?

Troj/Emotet-CLF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment