Malware

Troj/Emotet-CND (file analysis)

Malware Removal

The Troj/Emotet-CND is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CND virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings

How to determine Troj/Emotet-CND?


File Info:

crc32: DED0ADFB
md5: 34d49c60afe2701876f70c38f7729ad7
name: 34D49C60AFE2701876F70C38F7729AD7.mlw
sha1: 380020a3939ae3954948f72e13e38e981803a541
sha256: 71aad9e59cb77874ede0889ff6b656f66581b96fd0f7038bbabf9d51e48f3813
sha512: 3d6437a2dde05e9e2592e4f6fbe6d34c6cddf29109c08aee8b59cb45cab3969b0d389a235a1aaccd18d9174a8d022d1c611c0bfa0c069b773bf91ac917edb497
ssdeep: 12288:hKZia4Kjqs/CWd4Mmr6nTmQq+6iV7PNd:hKwDXs/CWd44q+lPNd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Emotet-CND also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.EmotetU.Gen.MqW@eOViR8Fi
McAfeeEmotet-FSD!34D49C60AFE2
K7AntiVirusTrojan ( 0056e14e1 )
BitDefenderTrojan.EmotetU.Gen.MqW@eOViR8Fi
K7GWTrojan ( 0056e14e1 )
BitDefenderThetaGen:NN.ZexaF.34634.MqW@aOViR8Fi
CyrenW32/Emotet.ASG.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.11b10f1b
Ad-AwareTrojan.EmotetU.Gen.MqW@eOViR8Fi
SophosTroj/Emotet-CND
DrWebTrojan.DownLoader35.27024
InvinceaTroj/Emotet-CND
McAfee-GW-EditionBehavesLike.Win32.Emotet.jm
FireEyeGeneric.mg.34d49c60afe27018
EmsisoftTrojan.EmotetU.Gen.MqW@eOViR8Fi (B)
IkarusTrojan-Banker.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.EmotetU.Gen.E5C7E1
GDataTrojan.EmotetU.Gen.MqW@eOViR8Fi
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R350923
VBA32BScope.Trojan.Zenpak
ALYacTrojan.EmotetU.Gen.MqW@eOViR8Fi
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HGFL
RisingTrojan.Kryptik!8.8 (TFE:4:DEHNsBy3odH)
FortinetW32/GenericKDZ.7010!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM20.1.44A7.Malware.Gen

How to remove Troj/Emotet-CND?

Troj/Emotet-CND removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment