Trojan

Trojan-Banker.Win32.Emotet.gayr removal tips

Malware Removal

The Trojan-Banker.Win32.Emotet.gayr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gayr virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Emotet.gayr?


File Info:

crc32: DE844540
md5: b6a2896068df2d30102a18229815fe35
name: upload_file
sha1: 88778547719549703b9183293630882ac87d8742
sha256: 668536ddf9e49227b4abcbafc68b5a04d656a6223fde70e1b0132aacd8ba4440
sha512: c533e5979a4606bf79249b09774d75640277f862ae88debab68647344f64b1cf41c231ab5f49bb094d81503b61db947d658ae81659282d9d5ac7046abcb6eed2
ssdeep: 3072:dpocVfb++Xuy7YXDxaOhlSMkpkxno3mOuT1UPKicuTZZIAZFXdKekyOI:nDZ++eNTxyMykuc1U7cuTV3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Emotet.gayr also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69449
FireEyeTrojan.GenericKDZ.69449
Qihoo-360Win32/Trojan.653
ALYacTrojan.GenericKDZ.69449
CylanceUnsafe
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusTrojan ( 0056c8201 )
BitDefenderTrojan.GenericKDZ.69449
K7GWTrojan ( 0056c8201 )
F-ProtW32/Emotet.APS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HFMZ
TrendMicro-HouseCallTROJ_GEN.R002C0DHF20
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.gayr
AlibabaTrojan:Win32/Emotet.3b0572a3
ViRobotTrojan.Win32.Emotet.188416.B
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKDZ.69449
TACHYONBackdoor/W32.Emotet.188416
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/AD.Emotet.anb
DrWebTrojan.Emotet.1000
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DHF20
SophosTroj/Emotet-CLB
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.APS.gen!Eldorado
JiangminBackdoor.Emotet.qv
AviraTR/AD.Emotet.anb
FortinetW32/Kryptik.HFMI!tr
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
ArcabitTrojan.Generic.D10F49
AhnLab-V3Trojan/Win32.Emotet.R348051
ZoneAlarmTrojan-Banker.Win32.Emotet.gayr
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 85)
McAfeeRDN/EmotetMLFNG
MAXmalware (ai score=82)
VBA32Backdoor.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
TencentWin32.Trojan-banker.Emotet.Pgmk
GDataTrojan.GenericKDZ.69449
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Banker.Win32.Emotet.gayr?

Trojan-Banker.Win32.Emotet.gayr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment