Trojan

Trojan-Banker.Win32.Emotet.evnz information

Malware Removal

The Trojan-Banker.Win32.Emotet.evnz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.evnz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Trojan-Banker.Win32.Emotet.evnz?


File Info:

crc32: B16CA6CE
md5: 70ab3889d9c1ffbea3f458d0b548044b
name: NCYGbmSRClqL9Cnf.exe
sha1: bdf1a918d37c668c8a07badc071a286215bcc8d6
sha256: 36358eb7c2726bf8eab063f7c309f447db35bd8a8de8c4050533ad8d60634ef4
sha512: 26645f34985e6b04685f83861a91c0063ad709dcc54d6307ea423547a423007c7ed1350640f49dccf482488e3a6fcaf74549803679b1e8933f6a5e3a6cec5612
ssdeep: 12288:I+KwRfM+2bkaweqUQ6FWR/zRgvf1IKBw6J21rIL3+x/FPY:dKeU+HawrIgXgX1D6ro
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: The Senate trial now moves into a two-day period of questioning
InternalName: President Trump was impeached on charges of abuse of power
FileVersion: 1.0.0.1
CompanyName: The president's defence wrapped up its arguments early on Tuesday
ProductName: Maine's Susan Collins, a vulnerable Republican who is up for
ProductVersion: 1.0.0.1
FileDescription: Jay Sekulow, the president's personal lawyer, said:
OriginalFilename: I think it's increasingly likely that other Republicans will join those
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.Emotet.evnz also known as:

McAfeeRDN/Emotet
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.33007202
K7GWRiskware ( 0040eff71 )
CyrenW32/Emotet.VCZJ-0941
ESET-NOD32a variant of Win32/GenKryptik.EDCC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.evnz
ViRobotTrojan.Win32.Emotet.472064
Ad-AwareTrojan.GenericKD.33007202
F-SecureTrojan.TR/AD.Emotet.enzzi
DrWebTrojan.DownLoader32.53983
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
FortinetW32/Malicious_Behavior.VEX
Trapminemalicious.moderate.ml.score
FireEyeTrojan.GenericKD.33007202
IkarusTrojan.Win32.Krypt
F-ProtW32/Emotet.ANT
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.enzzi
MAXmalware (ai score=86)
ZoneAlarmTrojan-Banker.Win32.Emotet.evnz
MicrosoftTrojan:Win32/Emotet!ibt
AhnLab-V3Malware/Win32.Generic.C3976296
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.VSNTAU20
RisingTrojan.Generic@ML.81 (RDML:xgzJHPW3aKXnLNAndStPGw)
GDataWin32.Trojan-Spy.Emotet.CS2OVU
BitDefenderThetaGen:NN.ZexaF.34084.CmLfauo3EVci

How to remove Trojan-Banker.Win32.Emotet.evnz?

Trojan-Banker.Win32.Emotet.evnz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment