Trojan

How to remove “Trojan-Banker.Win32.Emotet.erwu”?

Malware Removal

The Trojan-Banker.Win32.Emotet.erwu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.erwu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Emotet.erwu?


File Info:

crc32: 146AFBD8
md5: 06fb929129b647d245d2aeafc01a30ab
name: w7oovSaRMOps.exe
sha1: 94c48330bb0cd8b616fa018d27ad675b152fc20c
sha256: 73c95e18640c0ca18823deb111675be1ad44e522fa056c82ab9de4a9b6e2bd6a
sha512: 5162ee196bc7d0e20d17d3bd93cc826d9b035b4249a72773f146cd462fa2ee2c9e29ee9d5d9bbda90aa7e75dbebe0d28b3a973e4e643534c109986ad4f12a60b
ssdeep: 6144:D8lZHyvt2NrWAfAe2YNkZT2Nt0qxQaBXOgMUPVNBAH9wXkCqSl/Tpc325:KHyl2kKAc/Nt0qxZMUPr0pa/m32
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: OutlookTabCtrl
FileVersion: 1.0
ProductName: OutlookTabCtrl
ProductVersion: 1.0
FileDescription: OutlookTabCtrl
OriginalFilename: OutlookTabCtrl.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Emotet.erwu also known as:

DrWebTrojan.DownLoader32.51742
MicroWorld-eScanTrojan.GenericKD.32976671
ALYacTrojan.Agent.Emotet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32976671
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0bb0cd
TrendMicroTrojan.Win32.WACATAC.THABBBO
BitDefenderThetaGen:NN.ZexaF.34084.Aq1@aKbeYvak
SymantecPacked.Generic.554
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-7557679-0
GDataTrojan.GenericKD.32976671
KasperskyTrojan-Banker.Win32.Emotet.erwu
AlibabaTrojan:Win32/GenKryptik.71504495
AegisLabRiskware.Win32.Generic.1!c
RisingTrojan.Generic@ML.94 (RDML:iw+c9BZ64rJjo9GXUdBt8A)
Ad-AwareTrojan.GenericKD.32976671
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Emotet.hgyvw
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.06fb929129b647d2
EmsisoftTrojan.GenericKD.32976671 (B)
IkarusTrojan-Banker.Emotet
WebrootW32.Trojan.Gen
AviraTR/AD.Emotet.hgyvw
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F72F1F
ZoneAlarmTrojan-Banker.Win32.Emotet.erwu
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Malware/Win32.RL_Generic.R319268
McAfeeEmotet-FPT!06FB929129B6
VBA32Trojan.Emotet
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HAMM
TrendMicro-HouseCallTrojan.Win32.WACATAC.THABBBO
TencentWin32.Trojan-banker.Emotet.Hzf
SentinelOneDFI – Suspicious PE
PandaTrj/Emotet.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Banker.Win32.Emotet.erwu?

Trojan-Banker.Win32.Emotet.erwu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment