Trojan

Trojan-Banker.Win32.Emotet.fain removal

Malware Removal

The Trojan-Banker.Win32.Emotet.fain is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.fain virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.Emotet.fain?


File Info:

crc32: E27D9006
md5: f89fd04478e69923a348c807c03fa9e8
name: yas14.exe
sha1: e1ff79e090c775f514f80ecf408d4d7b7f1b035a
sha256: c18468e00d4027b583e9dbdbbfa97084baec49745b148fa6aafa8371f031d5f6
sha512: 7b479eec3b8e7458e8deafb07f0b2df91deff4301cca1453647b4f71262a0ed920d060491e71ee5335f549596ab492fb725b86437bac8917015e08273ba25e1a
ssdeep: 12288:dI1mUn5/c1PCrCehtlw/5XvuznmoPKGWPGr/fq:YmY5/c1PCmT/SPDWPGLC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2016
InternalName: Scanner
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Scanner x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: Scanner Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: Scanner.EXE
Translation: 0x0804 0x04b0

Trojan-Banker.Win32.Emotet.fain also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33370794
FireEyeGeneric.mg.f89fd04478e69923
Qihoo-360Trojan.Generic
McAfeeRDN/Generic.grp
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005615461 )
BitDefenderTrojan.GenericKD.33370794
K7GWTrojan ( 005615461 )
Cybereasonmalicious.090c77
TrendMicroTROJ_GEN.R011C0DBQ20
CyrenW32/Trojan.IFQT-6440
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Emotet-7600222-0
GDataTrojan.GenericKD.33370794
KasperskyTrojan-Banker.Win32.Emotet.fain
AlibabaTrojan:Win32/Emotet.0620fe90
NANO-AntivirusTrojan.Win32.Emotet.hcttuk
ViRobotTrojan.Win32.Trickbot.610304.F
AvastWin32:BankerX-gen [Trj]
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Ad-AwareTrojan.GenericKD.33370794
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.iahmu
DrWebTrojan.Packed.140
McAfee-GW-EditionRDN/Generic.grp
EmsisoftTrojan.Crypt (A)
SentinelOneDFI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Kryptik.iahmu
Antiy-AVLGrayWare/Win32.Generic
ArcabitTrojan.Generic.D1FD32AA
ZoneAlarmTrojan-Banker.Win32.Emotet.fain
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
BitDefenderThetaGen:NN.ZexaF.34090.Ly1@a0fcgTib
ALYacTrojan.Trickster.Gen
MAXmalware (ai score=100)
VBA32BScope.TrojanBanker.Emotet
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HBMJ
TrendMicro-HouseCallTROJ_GEN.R011C0DBQ20
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Malicious_Behavior.VEX
AVGWin32:BankerX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan-Banker.Win32.Emotet.fain?

Trojan-Banker.Win32.Emotet.fain removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment