Trojan

Trojan-Banker.Win32.Emotet.fujr removal guide

Malware Removal

The Trojan-Banker.Win32.Emotet.fujr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.fujr virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

How to determine Trojan-Banker.Win32.Emotet.fujr?


File Info:

crc32: C3912D20
md5: ab9ae90707c2f741bb06d17cc1fb4205
name: upload_file
sha1: 1beb3cd6168164e6d1ac3f2476484ae9b1adaf45
sha256: 6f147f751a481b3868e6f133ec981baab6650cafc751b023316701908ad9e7df
sha512: c52d7120a79eb337d9dbee866d653c8a26802959650f999e72ae9746d8dc872660e3fe19d84f6f19b6ea681fb58f53ef0832a4de6d45c3f8c8922c9f78999545
ssdeep: 768:i/nWA2nOGjqJLAjuTfO7edu+wsl/BBELfSoD/GlTZBpctd24CUryp1NWxJsvtDj:C2nOIwpOyu+ws/yLmlTZrUrO1NWx+3q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: rcversion
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: rcversion Application
ProductVersion: 1, 0, 0, 1
FileDescription: rcversion MFC Application
OriginalFilename: rcversion.EXE
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Emotet.fujr also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.DownLoader34.21865
MicroWorld-eScanTrojan.GenericKDZ.69388
FireEyeGeneric.mg.ab9ae90707c2f741
McAfeeEmotet-FQS!AB9AE90707C2
BitDefenderTrojan.GenericKDZ.69388
K7GWTrojan ( 00565dfa1 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaE.34152.eq0@a4XbW8pi
F-ProtW32/Kryptik.BTH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Banker.Win32.Emotet.fujr
RisingDownloader.Obfuse!8.105AD (TFE:dGZlOgXGtUlfUOqTbA)
Ad-AwareTrojan.GenericKDZ.69388
SophosTroj/Emotet-CKX
Invinceaheuristic
FortinetW32/GenKryptik.EJPF!tr
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
CyrenW32/Kryptik.BTH.gen!Eldorado
MAXmalware (ai score=81)
ZoneAlarmTrojan-Banker.Win32.Emotet.fujr
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R347569
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HFMI
SentinelOneDFI – Suspicious PE
GDataTrojan.GenericKDZ.69388
Cybereasonmalicious.616816

How to remove Trojan-Banker.Win32.Emotet.fujr?

Trojan-Banker.Win32.Emotet.fujr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment