Trojan

Trojan-Banker.Win32.Emotet.eauh (file analysis)

Malware Removal

The Trojan-Banker.Win32.Emotet.eauh file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Banker.Win32.Emotet.eauh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Emotet.eauh?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Mal/EncPk-APC

File Info:

Name: OaFmUDNwOR2YpC.exe

Size: 748459

Type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

MD5: 86483d04edd60b34ea8af43307a2a6f7

SHA1: fb311143b19a7a1b1c0435911ead55f74cc94e16

SH256: f7544f4abb5a740a76626987b87187716163314d7983a2ce697726460e673e71

Version Info:

[No Data]

Trojan-Banker.Win32.Emotet.eauh also known as:

ALYacTrojan.GenericKD.42011308
APEXMalicious
AVGWin32:Malware-gen
Ad-AwareTrojan.GenericKD.42012671
AegisLabTrojan.Win32.Generic.4!c
AhnLab-V3Malware/Win32.Generic.C3560827
AlibabaTrojan:Win32/Emotet.8a2c9479
Antiy-AVLTrojan[Banker]/Win32.Emotet
ArcabitTrojan.Generic.D2810FFF
AvastWin32:Malware-gen
AviraTR/AD.Emotet.roaur
BitDefenderTrojan.GenericKD.42012671
BitDefenderThetaGen:NN.ZexaF.32250.TOX@aW9wnJe
ComodoMalware@#19oucq18et2pj
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.3b19a7
CyrenW32/Kryptik.AQH.gen!Eldorado
DrWebTrojan.DownLoader30.38842
ESET-NOD32a variant of Win32/Kryptik.GYGC
Endgamemalicious (high confidence)
F-ProtW32/Kryptik.AQH.gen!Eldorado
F-SecureTrojan.TR/AD.Emotet.roaur
FireEyeGeneric.mg.86483d04edd60b34
FortinetW32/GenKryptik.DXOD!tr
GDataTrojan.GenericKD.42012671
IkarusTrojan-Banker.Emotet
Invinceaheuristic
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyTrojan-Banker.Win32.Emotet.eauh
McAfeeRDN/Emotet-Dropped
McAfee-GW-EditionRDN/Emotet-Dropped
MicroWorld-eScanTrojan.GenericKD.42012671
MicrosoftTrojan:Win32/Emotet.SM!MSR
Paloaltogeneric.ml
PandaTrj/Genetic.gen
Qihoo-360Win32/Trojan.28f
RisingTrojan.Generic@ML.93 (RDML:bn6PTkNvKGRUSKJ2Ix8u/w)
SentinelOneDFI – Suspicious PE
SophosMal/EncPk-APC
SymantecTrojan Horse
TrendMicro-HouseCallTROJ_GEN.R03FC0DKD19
VBA32BScope.TrojanBanker.Emotet
VIPRETrojan.Win32.Generic!BT
WebrootW32.Malware.gen
ZoneAlarmTrojan-Banker.Win32.Emotet.eauh

How to remove Trojan-Banker.Win32.Emotet.eauh?

Trojan-Banker.Win32.Emotet.eauh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment