Malware

Troj/Emotet-CLL removal instruction

Malware Removal

The Troj/Emotet-CLL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CLL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Emotet-CLL?


File Info:

crc32: E8DD058B
md5: f2878fa18d8b0e2f2b9ced6bdb1f9869
name: UUMAsRf.exe
sha1: 05de2a56a4dc94f68bf6bfc644629fcc4ba113a2
sha256: ffc1b7f7096aa3007230bf917cb59fdbed1f4f27263c3166ab33027d57afdb05
sha512: ed48fd5328fb9241c522f344d3b6ac808e0984e4c4ca00809582ca58cc1125b7c035163cbb07de5f2d540355f5890dc8aab2d3e0bb69d07f89f9579f945a9b3c
ssdeep: 1536:8RucTgvK09KTbheJJowUQLweYYpEuEX/PokElw7wyBTgT/Ac:8vgCrheJJowPkeYoEuEPLJwYTgAc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Emotet-CLL also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EVEX
FireEyeTrojan.Agent.EVEX
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FRV!F2878FA18D8B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.EVEX
K7GWRiskware ( 0040eff71 )
CyrenW32/Emotet.AQM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R002C0DHL20
KasperskyTrojan-Banker.Win32.Emotet.gccp
AlibabaTrojan:Win32/Emotet.19d15738
NANO-AntivirusTrojan.Win32.Emotet.hrvuqo
ViRobotTrojan.Win32.Emotet.274432
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.Agent.EVEX
TACHYONBackdoor/W32.Emotet.180333
F-SecureTrojan.TR/Emotet.pvddl
DrWebTrojan.Emotet.999
TrendMicroTROJ_GEN.R002C0DHL20
SophosTroj/Emotet-CLL
APEXMalicious
JiangminBackdoor.Emotet.sf
AviraTR/Emotet.pvddl
Antiy-AVLTrojan/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.PED!MTB
ArcabitTrojan.Agent.EVEX
AhnLab-V3Trojan/Win32.Emotet.R348890
ZoneAlarmTrojan-Banker.Win32.Emotet.gccp
GDataWin32.Trojan.PSE.1NF0C60
VBA32Trojan.Wacatac
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.TRE
IkarusTrojan-Banker.Emotet
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10cde9e5
FortinetW32/Kryptik.HCEJ!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Troj/Emotet-CLL?

Troj/Emotet-CLL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment