Malware

Troj/Emotet-CLZ removal guide

Malware Removal

The Troj/Emotet-CLZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CLZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Emotet-CLZ?


File Info:

crc32: EF87B488
md5: f0eb0aad885f53e04159ad68874e8e25
name: upload_file
sha1: 59f3afe63dc64aa22ddbee7e946550e4adf53032
sha256: 5317f597418505162db361de20fa2fa0b51840e243309c1042d688f57fb67d51
sha512: cc3ec53103808d0965c7dc2468f681ad1d2c1bea92d275c219eef2e47b432f03dc35ccf5dcb473f1ca96ab79f5d2973fb35f999a5c2fc204c49f46dc4737db39
ssdeep: 12288:r2vTqjC1nHI7KfQMbwB+wSSlbDoccv4QkNmS:r2GO1nHJQMUDnbEYQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Free to redistribute!
InternalName: cmdcmxcfg.exe
FileVersion: 1.0.0.1
CompanyName: Shaun Harrington
ProductName: CMDCMX
ProductVersion: 1.0.0.1
FileDescription: CMDCMX Configuration Application
OriginalFilename: cmdcmxcfg.exe
Translation: 0x0409 0x04e4

Troj/Emotet-CLZ also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43786276
CAT-QuickHealTrojan.EmotetPMF.S15717669
ALYacTrojan.Agent.Emotet
CylanceUnsafe
ZillyaTrojan.Emotet.Win32.28390
K7AntiVirusTrojan ( 005600f21 )
BitDefenderTrojan.GenericKD.43786276
K7GWTrojan ( 0056de091 )
TrendMicroTrojan.Win32.MALREP.THJOFBO
CyrenW32/Kryptik.BWJ.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Malware.Emotet-9753021-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.vho
AlibabaTrojan:Win32/Emotet.c21952a5
NANO-AntivirusTrojan.Win32.Emotet.hueocq
ViRobotTrojan.Win32.Emotet.335360
AegisLabTrojan.Win32.Emotet.truE
Ad-AwareTrojan.GenericKD.43786276
SophosTroj/Emotet-CLZ
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Emotet.youls
DrWebTrojan.Emotet.1016
VIPRETrojan.Win32.Generic!BT
InvinceaTroj/Emotet-CLZ
McAfee-GW-EditionBehavesLike.Win32.Emotet.dm
MaxSecureTrojan.Malware.121218.susgen
FireEyeGeneric.mg.f0eb0aad885f53e0
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.oig
AviraTR/Emotet.youls
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D29C2024
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.vho
GDataTrojan.GenericKD.43786276
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4192704
McAfeeEmotet-FSD!F0EB0AAD885F
MAXmalware (ai score=83)
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/CI.A
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTrojan.Win32.MALREP.THJOFBO
RisingTrojan.Emotet!1.CBD1 (CLASSIC)
YandexTrojan.Emotet!
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.HFZC!tr
BitDefenderThetaGen:NN.ZexaF.34566.9q3@auwM5Bbi
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.bd3

How to remove Troj/Emotet-CLZ?

Troj/Emotet-CLZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment