Trojan

Trojan-Banker.Win32.Emotet.ewet removal tips

Malware Removal

The Trojan-Banker.Win32.Emotet.ewet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.ewet virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Trojan-Banker.Win32.Emotet.ewet?


File Info:

crc32: 68D74520
md5: 4558377eeed03140f7e5bba1cc3e9f98
name: dcPyP11y2nWhW.exe
sha1: 4ad661aa3b5433eae1835707feb0842348605fe9
sha256: a1e94638002bf77803028106ddf478ee39f78d50903ea8e40b257a3e91f50b03
sha512: 4d5e790b2c8ce43eff09f727f9c00b33a7691d49d8c52d53d51a838788ba88029af3b258bffe4861e0a5f2417c39d60938adf41690ecc697490d3bb5e2b1ad43
ssdeep: 6144:gFDL8wzTclV4uepaRNLmh4ou8HWV9FKEBuwHO63g6v/U1K8xVMIuk4aM1Odl:8n8wzTclaueQIh4ouhZKEQN1WsE8xZM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Republicans have variously argued that Trump did nothing wrong
InternalName: door to foreign nations keen to see him stay in office
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: who did not agree with him treated Republican and Democratic
ProductVersion: 1, 0, 0, 1
FileDescription: Acquitting Trump on such grounds could also open
OriginalFilename: impeachment charges or that there was no quid pro quo in Ukraine
Translation: 0x0804 0x04b0

Trojan-Banker.Win32.Emotet.ewet also known as:

MicroWorld-eScanTrojan.GenericKD.33009039
FireEyeGeneric.mg.4558377eeed03140
ALYacDeepScan:Generic.TrickBot.2.A7FC2DCD
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33009039
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a3b543
TrendMicroTROJ_FRS.0NA103AV20
BitDefenderThetaGen:NN.ZexaF.34084.xmLfaaBDgnnb
F-ProtW32/Agent.BNN.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Emotet-7570451-1
GDataTrojan.GenericKD.33009039
KasperskyTrojan-Banker.Win32.Emotet.ewet
AlibabaTrojan:Win32/Emotet.ee57f433
Ad-AwareTrojan.GenericKD.33009039
EmsisoftTrojan.GenericKD.33009039 (B)
F-SecureTrojan.TR/AD.Emotet.oppnn
McAfee-GW-EditionBehavesLike.Win32.LiveSoftAction.fc
Trapminemalicious.high.ml.score
SophosMal/Encpk-APE
IkarusTrojan-Banker.Emotet
CyrenW32/Agent.BNN.gen!Eldorado
JiangminTrojan.Banker.Emotet.nfa
AviraTR/AD.Emotet.oppnn
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D1F7AD8F
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan-Banker.Win32.Emotet.ewet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Malware/Win32.RL_Generic.R325180
McAfeeGenericRXAA-AA!4558377EEED0
MAXmalware (ai score=80)
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HASD
TrendMicro-HouseCallTROJ_FRS.0NA103AV20
RisingTrojan.Generic@ML.94 (RDML:Z2tzHhg+8ihakas/Mv3rMw)
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HASD!tr
WebrootW32.Trojan.Emotet
AVGFileRepMalware
PandaTrj/Emotet.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Banker.Win32.Emotet.ewet?

Trojan-Banker.Win32.Emotet.ewet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment