Trojan

What is “Trojan-Banker.Win32.Emotet.fkou”?

Malware Removal

The Trojan-Banker.Win32.Emotet.fkou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.fkou virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r4—sn-4g5ednsy.gvt1.com

How to determine Trojan-Banker.Win32.Emotet.fkou?


File Info:

crc32: 1B88C74B
md5: 27c2a76b7b8bb9ec9eb5e7f1376be3fa
name: upload_file
sha1: c709c5e7f1c27da33bda467d01c4f05173b3e965
sha256: bb696c7c19d13cb13bfaa678a9d86167bc018c2d73f77f6c750c68e9679df4a4
sha512: 991461ea21c259fcda7b996a64260a0628db0fdf5be1d65f0e6ec3f9323778aa524838f4b9a2ba5228c18f0ad1b0660f88d1a69ada1e4419bb43f0cb136db8ee
ssdeep: 3072:BQAtEQkstBPSlDW/i/WUWHLiMrHLCjJK0ToGd:BLEOVSpW6CHOMrHkMm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Emotet.fkou also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Agent.EUIE
FireEyeTrojan.Agent.EUIE
ALYacTrojan.Agent.EUIE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056aa7c1 )
BitDefenderTrojan.Agent.EUIE
K7GWTrojan ( 0056aa7c1 )
TrendMicroTROJ_GEN.R002C0DGV20
F-ProtW32/Emotet.AOH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HEWN
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
Paloaltogeneric.ml
GDataTrojan.Agent.EUIE
KasperskyTrojan-Banker.Win32.Emotet.fkou
AlibabaTrojan:Win32/Emotet.fc86d160
NANO-AntivirusTrojan.Win32.Emotet.hpnmal
AegisLabTrojan.Win32.Euie.4!c
APEXMalicious
RisingTrojan.Kryptik!1.C89F (CLOUD)
Ad-AwareTrojan.Agent.EUIE
SophosTroj/Emotet-CKN
DrWebTrojan.DownLoader34.14035
ZillyaBackdoor.Emotet.Win32.841
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.AOH.gen!Eldorado
JiangminBackdoor.Emotet.ph
AviraTR/Crypt.Agent.gukth
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Injuke
ArcabitTrojan.Agent.EUIE
AhnLab-V3Malware/Win32.Generic.C4172970
ZoneAlarmTrojan-Banker.Win32.Emotet.fkou
MicrosoftTrojan:Win32/Emotet.AER!MTB
CynetMalicious (score: 85)
McAfeeEmotet-FRI!27C2A76B7B8B
TACHYONBanker/W32.Emotet.225280.R
VBA32Trojan.Emotet
MalwarebytesTrojan.MalPack.TRE
TencentMalware.Win32.Gencirc.10cde55b
FortinetW32/GenKryptik.EOMR!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.e47

How to remove Trojan-Banker.Win32.Emotet.fkou?

Trojan-Banker.Win32.Emotet.fkou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment