Malware

About “Troj/Emotet-CSI” infection

Malware Removal

The Troj/Emotet-CSI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CSI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Emotet-CSI?


File Info:

crc32: 5A9C5A38
md5: bc01a9f589f3770f91ade2db1a90643b
name: jqTFQx5zURsKCa1rvQc.exe
sha1: ebf571c4eae749f6ef0ac5cbd3393ae6687e0ff0
sha256: d9c7beb0980b855d3bc1118e23cb4b2d37c50d94e64e90f30abccf09cba446ab
sha512: 17bc7d2e602a3a252badc2288c9dcc41ea5399b6bf8c87a1afb9dfd6ab49732fe01637500c85fbc350981e73336f5e6cb117239fc347b32e54af4923d1926c5e
ssdeep: 12288:zXsObAC+H3bd40FM1OpzEt4t/tltJt004m6E0p:zzMC+HTFM1OpzenF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: CCircFileDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CCircFileDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: CCircFileDemo MFC Application
OriginalFilename: CCircFileDemo.EXE
Translation: 0x0409 0x04b0

Troj/Emotet-CSI also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EYFR
FireEyeGeneric.mg.bc01a9f589f3770f
McAfeeEmotet-FSF!BC01A9F589F3
CylanceUnsafe
AegisLabTrojan.Win32.Emotet.L!c
BitDefenderTrojan.Agent.EYFR
TrendMicroTrojanSpy.Win32.EMOTET.SMU.hp
BitDefenderThetaGen:NN.ZexaF.34590.Au0@aKkhoGki
CyrenW32/Kryptik.APD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Trojan.Emotetu-9784444-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
RisingTrojan.Generic@ML.83 (RDMK:9SJgJ50TNoGfpvSxHwzsew)
Ad-AwareTrojan.Agent.EYFR
SophosTroj/Emotet-CSI
DrWebTrojan.Emotet.1046
InvinceaMal/Generic-S + Troj/Emotet-CSI
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
EmsisoftTrojan.Emotet (A)
WebrootW32.Trojan.Emotet
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
ArcabitTrojan.Agent.EYFR
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataTrojan.Agent.EYFR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R354300
Acronissuspicious
ALYacTrojan.Agent.Emotet
TACHYONTrojan/W32.Agent.428032.UB
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HHBE
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMU.hp
IkarusTrojan-Banker.Emotet
FortinetW32/BankerX.5CC7!tr
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.adb

How to remove Troj/Emotet-CSI?

Troj/Emotet-CSI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment