Malware

Troj/Emotet-CTC removal instruction

Malware Removal

The Troj/Emotet-CTC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CTC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Emotet-CTC?


File Info:

crc32: 50CF2E6A
md5: 233aa37ab86d33eac570aff82c8dc400
name: 233AA37AB86D33EAC570AFF82C8DC400.mlw
sha1: 798645f122d1b8ede9122a4e10c69f0047d875e7
sha256: a7fe02ff5bfef61b9d2344b8b8cc225f988f0f354220b564457231e4d98d21fb
sha512: 326f3540b624773799643303273a5e712cb1569ae1846edd0dde73d056f1b414fbd82ac1e681a464eea8f03b471035b22c8cf844fc8ae61c94c5ac170982ebcd
ssdeep: 12288:iddpBzWVqTWbJu/zYqVZ5PNZhUC1GQD66i:6qVqTWFKYqVZ51FJt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: MDI_Notepad
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MDI_Notepad Application
ProductVersion: 1, 0, 0, 1
FileDescription: MDI_Notepad MFC Application
OriginalFilename: MDI_Notepad.EXE
Translation: 0x0409 0x04b0

Troj/Emotet-CTC also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.333403
FireEyeGeneric.mg.233aa37ab86d33ea
ALYacGen:Variant.Zusy.333403
BitDefenderGen:Variant.Zusy.333403
CyrenW32/Emotet.AWS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Dropper.Emotet-9789045-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
RisingTrojan.Emotet!8.B95 (TFE:5:etz1VblbGQH)
Ad-AwareGen:Variant.Zusy.333403
EmsisoftGen:Variant.Zusy.333403 (B)
DrWebTrojan.DownLoader35.13759
InvinceaTroj/Emotet-CTC
McAfee-GW-EditionBehavesLike.Win32.Emotet.hh
SophosTroj/Emotet-CTC
WebrootW32.Trojan.Gen
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Emotetcrypt.VM!MTB
ArcabitTrojan.Zusy.D5165B
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.pef
GDataWin32.Trojan.PSE.1HJ66QH
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.C4221023
McAfeeEmotet-FSJ!233AA37AB86D
VBA32BScope.TrojanBanker.Emotet
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HHJZ
FortinetW32/Kryptik.HEOE!tr
BitDefenderThetaGen:NN.ZexaF.34634.Iu0@aWyvmkoi
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.74647709.susgen

How to remove Troj/Emotet-CTC?

Troj/Emotet-CTC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment