Trojan

About “Trojan-Banker.Win32.Emotet.eahp” infection

Malware Removal

The Trojan-Banker.Win32.Emotet.eahp file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Banker.Win32.Emotet.eahp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Emotet.eahp?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Trojan.Generic@ML.94 (RDML:eMZ9PTKEj980fnzBgUVmXw)

File Info:

Name: l1qhec13plss2ox.exe

Size: 748833

Type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

MD5: 0b3acf106862142bab65f25c3d5f33d9

SHA1: e99274eaee1358a70efc98d569aab35318e9b1ec

SH256: a87b30775c08fab67e47690165049f857f175524a32b18c4d6aa7e8efeaca20f

Version Info:

[No Data]

Trojan-Banker.Win32.Emotet.eahp also known as:

ALYacTrojan.Agent.Emotet
AVGFileRepMalware
Ad-AwareTrojan.Autoruns.GenericKDS.32704618
AegisLabTrojan.Win32.Emotet.L!c
AhnLab-V3Trojan/Win32.Emotet.R298664
AlibabaTrojan:Win32/Emotet.6c6bf3bb
Antiy-AVLTrojan/Win32.Casur
ArcabitTrojan.Autoruns.GenericS.D1F3086A
AviraTR/AD.Emotet.owart
BitDefenderTrojan.Autoruns.GenericKDS.32704618
BitDefenderThetaGen:NN.ZexaCO3.32249.TOX@aWtJ6dl
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.aee135
CyrenW32/Kryptik.AQA.gen!Eldorado
DrWebTrojan.Emotet.775
ESET-NOD32a variant of Win32/Kryptik.GYEZ
Endgamemalicious (high confidence)
F-ProtW32/Emotet.AAV.gen!Eldorado
F-SecureTrojan.TR/AD.Emotet.owart
FireEyeGeneric.mg.0b3acf106862142b
FortinetW32/Dapato.PZNU!tr
GDataTrojan.Autoruns.GenericKDS.32704618
IkarusTrojan-Banker.Emotet
Invinceaheuristic
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyTrojan-Banker.Win32.Emotet.eahp
MAXmalware (ai score=84)
MalwarebytesTrojan.Injector
McAfeeEmotet-FOL!0B3ACF106862
McAfee-GW-EditionBehavesLike.Win32.Ransomware.bh
MicroWorld-eScanTrojan.Autoruns.GenericKDS.32704618
MicrosoftTrojan:Win32/Emotet.SK!MSR
NANO-AntivirusTrojan.Win32.Emotet.ggtvtw
Paloaltogeneric.ml
PandaTrj/Agent.PM
Qihoo-360Win32/Trojan.434
RisingTrojan.Generic@ML.94 (RDML:eMZ9PTKEj980fnzBgUVmXw)
SentinelOneDFI – Malicious PE
SophosMal/Generic-S
SymantecTrojan Horse
Trapminemalicious.moderate.ml.score
TrendMicro-HouseCallTROJ_GEN.R03FC0DKC19
VBA32Trojan.Emotet
VIPRETrojan.Win32.Generic!BT
WebrootW32.Trojan.Gen
ZoneAlarmTrojan-Banker.Win32.Emotet.eahp

How to remove Trojan-Banker.Win32.Emotet.eahp?

Trojan-Banker.Win32.Emotet.eahp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment