Trojan

Trojan.Agent.ETOM removal

Malware Removal

The Trojan.Agent.ETOM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.ETOM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the Emotet malware family
  • Attempts to modify proxy settings

How to determine Trojan.Agent.ETOM?


File Info:

name: AF3F2AF1222CA6291ABD.mlw
path: /opt/CAPEv2/storage/binaries/dda232ef1e4636fd5eecdd85c1ff193ed8633ebf1aec858f4b519bdd9b09a063
crc32: B65E03D3
md5: af3f2af1222ca6291abd04904d2c5273
sha1: acd20cee7f35f44935d36ebd9711de9c1efdd65d
sha256: dda232ef1e4636fd5eecdd85c1ff193ed8633ebf1aec858f4b519bdd9b09a063
sha512: 937d2dc01872f4d8829a1c2854f8cb8966eb365f7af85fe05352490b1cfdac2f52799dc3c91078bf609774d6b12862499e3067bcb64926e0fb4e25ef9a96a9d3
ssdeep: 12288:Owu6a66hN2cCGN+Vw9FbvKYCUoaNshkHv:OMvApvb5oCP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13AA46B11FBC5D43AD65602724E93C67D6261BD52DE2086837BD07F8EAE30AC3E935B84
sha3_384: b083f2dd2a8590efa2ca9aa270dcaad8f91cb6f438a9e16214145e904efaaab07d43ceda85f3c944d8af8bb3786ff9e2
ep_bytes: e856a80000e916feffff6a00ff742414
timestamp: 2020-07-01 19:08:54

Version Info:

Comments:
CompanyName:
FileDescription: FtpClient MFC Application
FileVersion: 1, 0, 0, 1
InternalName: FtpClient
LegalCopyright: Copyright (C) 2005
LegalTrademarks:
OriginalFilename: mfcClient.EXE
PrivateBuild:
ProductName: FtpCilent Application
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Trojan.Agent.ETOM also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.DownLoader33.61787
MicroWorld-eScanTrojan.Agent.ETOM
FireEyeGeneric.mg.af3f2af1222ca629
ALYacTrojan.Agent.ETOM
VIPRETrojan.Agent.ETOM
K7AntiVirusTrojan ( 0056a4ba1 )
K7GWTrojan ( 0056a4ba1 )
Cybereasonmalicious.1222ca
VirITTrojan.Win32.TrickBot.BIR
CyrenW32/Trickbot.EE.gen!Eldorado
SymantecPacked.Generic.534
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HESX
APEXMalicious
ClamAVWin.Trojan.Emotet-9778624-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderTrojan.Agent.ETOM
NANO-AntivirusTrojan.Win32.Zenpak.hnhcmc
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cdde3d
Ad-AwareTrojan.Agent.ETOM
SophosMal/Generic-R + Troj/Emotet-CWI
ZillyaTrojan.Emotet.Win32.20996
TrendMicroTROJ_GEN.R047C0DHG22
McAfee-GW-EditionEmotet-FRG!AF3F2AF1222C
EmsisoftTrojan.Emotet (A)
IkarusTrojan.Win32.Crypt
GDataTrojan.Agent.ETOM
JiangminTrojan.Zenpak.cqn
GoogleDetected
AviraHEUR/AGEN.1209417
Antiy-AVLTrojan/Generic.ASMalwS.3F43
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.R343818
McAfeeEmotet-FRG!AF3F2AF1222C
MAXmalware (ai score=81)
VBA32BScope.Backdoor.Emotet
MalwarebytesTrojan.Emotet
TrendMicro-HouseCallTROJ_GEN.R047C0DHG22
RisingTrojan.Kryptik!1.C80B (CLASSIC)
YandexTrojan.Kryptik!g/cDXcvjyfo
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HESX!tr
AVGWin32:Trojan-gen
PandaTrj/Emotet.C
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.ETOM?

Trojan.Agent.ETOM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment