Malware

How to remove “Troj/Emotet-CLS”?

Malware Removal

The Troj/Emotet-CLS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CLS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempts to modify proxy settings

How to determine Troj/Emotet-CLS?


File Info:

crc32: D7DD432B
md5: 57d305afb946189cdeb82c131a0b0ceb
name: XJkNTcXC.exe
sha1: 83fa83dc813d774ce16a35d9c0a3ece144b05185
sha256: 9e7aadcb0fabd4fb5be04955849895c40ca4951c0efc42c95bc08b2594929253
sha512: ade8db68d46f4b660c3172e54c5a28316ceffe61578957f5d0dd5afbceeb3313e476b62c8228efafa555c41db7c18767df2b45feab0076e9f426e169b80e8c34
ssdeep: 12288:Hy2LNBEu2g2GJw77KyQiM3Uyj3/DEP7Nf:SaWFGJw77/QiMD4f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TODO: (c) . All rights reserved.
InternalName: SQLite Test.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: SQLite Test.exe
Translation: 0x0409 0x04e4

Troj/Emotet-CLS also known as:

MicroWorld-eScanTrojan.Agent.EVKP
FireEyeTrojan.Agent.EVKP
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FRV!57D305AFB946
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.EVKP
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R06CC0DHQ20
CyrenW32/Emotet.ARB.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.gcku
AlibabaTrojan:Win32/Emotet.1bf3dd97
NANO-AntivirusTrojan.Win32.Emotet.hszqaz
ViRobotTrojan.Win32.Emotet.397312.C
RisingTrojan.Kryptik!8.8 (TFE:5:vXCzrqbdBEF)
Ad-AwareTrojan.Agent.EVKP
EmsisoftTrojan.Agent.EVKP (B)
F-SecureTrojan.TR/AD.Emotet.ceunk
DrWebTrojan.Emotet.1005
ZillyaTrojan.Emotet.Win32.24965
InvinceaMal/Generic-R + Troj/Emotet-CLS
SophosTroj/Emotet-CLS
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.oez
MaxSecureTrojan.Malware.105913884.susgen
AviraTR/AD.Emotet.ceunk
MAXmalware (ai score=88)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.PED!MTB
ArcabitTrojan.Agent.EVKP
ZoneAlarmTrojan-Banker.Win32.Emotet.gcku
GDataWin32.Trojan.PSE.13LBU0F
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R349206
BitDefenderThetaGen:NN.ZexaF.34216.yq0@aOHAAKbi
ALYacTrojan.Agent.EVKP
TACHYONBanker/W32.Emotet.397312.I
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R06CC0DHQ20
TencentMalware.Win32.Gencirc.10cdee3b
YandexTrojan.Emotet!
FortinetW32/Zenpak.AUSL!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
Qihoo-360Win32/Trojan.ea3

How to remove Troj/Emotet-CLS?

Troj/Emotet-CLS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment