Malware

About “Troj/Emotet-CRW” infection

Malware Removal

The Troj/Emotet-CRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CRW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Troj/Emotet-CRW?


File Info:

crc32: 60417312
md5: 78cf60f79b29a73f1d3e0619301c803f
name: upload_file
sha1: 64aec6bbf2cf843d41bc702dd54dba430226bab9
sha256: 405205fea427cfcd09f6865608262e4091432df465bbbf84c7981dda0d78db75
sha512: e863d9a584aedd3c3afca4662fee1e7ac71543d65d35a3d0ccb607fc5b034c4b6fa61592e79d283cf3ef0e7074bb8f16419b50032945ea95a2fb4c49b73504c8
ssdeep: 12288:tkDwmoShmmp6EPCZG1UrIujTQSk+wn0Y4GBinko/4GCGKyZDE93AbWxPPywg:tWnhDpoGOrZjT/USING5E93AbW1+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TODO: (c) . All rights reserved.
InternalName: CalculatorControl.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: CalculatorControl.exe
Translation: 0x0409 0x04e4

Troj/Emotet-CRW also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70870
FireEyeGeneric.mg.78cf60f79b29a73f
McAfeeRDN/Emotet
CylanceUnsafe
K7AntiVirusTrojan ( 005716f01 )
BitDefenderTrojan.GenericKDZ.70870
K7GWTrojan ( 005716f01 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Emotet.AVO.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
AlibabaTrojan:Win32/EmotetCrypt.9c85a9e0
AegisLabTrojan.Win32.Emotet.L!c
RisingTrojan.Generic@ML.97 (RDML:bMNKi1MZbg23XuI8OPlFhQ)
Ad-AwareTrojan.GenericKDZ.70870
ComodoMalware@#3dp6cdlzscg0n
DrWebTrojan.DownLoader35.4825
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Emotet-CRW
McAfee-GW-EditionRDN/Emotet
SophosTroj/Emotet-CRW
IkarusTrojan-Banker.Emotet
eGambitUnsafe.AI_Score_86%
AviraTR/Emotet.kgcnx
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
ArcabitTrojan.Generic.D114D6
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataTrojan.GenericKDZ.70870
AhnLab-V3Trojan/Win32.Emotet.R353762
Acronissuspicious
VBA32BScope.Trojan.Emotet
PandaTrj/Emotet.C
ESET-NOD32Win32/Emotet.CM
TencentWin32.Trojan-banker.Emotet.Akfv
MaxSecureTrojan.Malware.11417434.susgen
FortinetW32/Emotet.CI!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.095

How to remove Troj/Emotet-CRW?

Troj/Emotet-CRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment