Trojan

Trojan-Banker.Win32.Emotet.gbny removal tips

Malware Removal

The Trojan-Banker.Win32.Emotet.gbny is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gbny virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

How to determine Trojan-Banker.Win32.Emotet.gbny?


File Info:

crc32: 8732D471
md5: 5fb96b374a645cb3947ab6ccb3a0b3ba
name: upload_file
sha1: 0132109f36598cf9a4737ee805decf01394a9286
sha256: 10c9174a6f70704bb2cb500f1fcd215cddd191c79c10421dae73a7654e4a7f92
sha512: 0787eb3f2dadc065141aac9d9fb024bbd338dbdd4fb233f3a72b5e6db190a03f3f9d34b7f74ae15c4ca4f5431fef41943c5787bd7568da4e8830f01d81ffa4fa
ssdeep: 12288:dk7/FTNhj7jMshXLdSi2usAX6Ov9Xo5+ZtZt0:EksdLdP2LmxtZO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Emotet.gbny also known as:

BkavW32.DelShadGTL.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69511
FireEyeTrojan.GenericKDZ.69511
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FRV!5FB96B374A64
ZillyaBackdoor.Emotet.Win32.1009
K7AntiVirusTrojan ( 005600261 )
BitDefenderTrojan.GenericKDZ.69511
K7GWTrojan ( 005600261 )
CyrenW32/Emotet.YRNT-5026
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.gbny
AlibabaTrojan:Win32/Emotet.460239e0
ViRobotTrojan.Win32.Emotet.655360.C
TencentMalware.Win32.Gencirc.10cde86b
Ad-AwareTrojan.GenericKDZ.69511
F-SecureTrojan.TR/Emotet.yiiop
DrWebTrojan.DownLoader34.24759
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DHI20
SophosTroj/Emotet-CLF
JiangminBackdoor.Emotet.rg
AviraTR/Emotet.yiiop
MAXmalware (ai score=81)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D10F87
ZoneAlarmTrojan-Banker.Win32.Emotet.gbny
GDataWin32.Trojan.PSE.126CQ22
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R348605
TACHYONTrojan/W32.Emotet.655360.B
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R011C0DHI20
RisingTrojan.Emotet!8.B95 (CLOUD)
IkarusTrojan-Banker.Emotet
FortinetW32/Emotet.6DC5!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM41.2.4E50.Malware.Gen

How to remove Trojan-Banker.Win32.Emotet.gbny?

Trojan-Banker.Win32.Emotet.gbny removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment