Trojan

Should I remove “Trojan-Banker.Win32.Emotet.gcwu”?

Malware Removal

The Trojan-Banker.Win32.Emotet.gcwu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gcwu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.Emotet.gcwu?


File Info:

crc32: 489A9EB3
md5: d5cfc8eae314baa1fab94e7035ece772
name: upload_file
sha1: 1ad1ff8d570cde642893211a1dd731f4ef5b1ddc
sha256: 2459a8fcfebbdd1b0d029d5aefbaba0754ed4029ed0e29d1d9d595c652abba6c
sha512: e24182c0f7c32296e965ca124681f0db7fbaab97785f50f0305dd3be163c7b203bc7d020580b59e8aa295eeb4fffe82a3768afd06688adbc341779ff03ef5932
ssdeep: 6144:cTaQZdJnaB1kNO/FSm9tc6c6c6c6c6c6c6c6c6csI+7L1NIDK:cGQfJ0FrZL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xb0xe6xc8xa8xcbxf9xd3xd0 (C) 2007
InternalName: TestDigitalControl
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: TestDigitalControl
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: TestDigitalControl Microsoft
OriginalFilename: TestDigitalControl.EXE
Translation: 0x0000 0x04b0

Trojan-Banker.Win32.Emotet.gcwu also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.Emotet.1005
MicroWorld-eScanTrojan.GenericKDZ.69819
FireEyeTrojan.GenericKDZ.69819
Qihoo-360Win32/Trojan.ef3
McAfeeEmotet-FRY!D5CFC8EAE314
CylanceUnsafe
K7AntiVirusTrojan ( 0056d77d1 )
BitDefenderTrojan.GenericKDZ.69819
K7GWTrojan ( 0056d77d1 )
TrendMicroTrojan.MSIL.WACATAC.USXVPHU20
BitDefenderThetaGen:NN.ZexaE.34196.1q0@aSkytImj
CyrenW32/Emotet.ARO.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Emotet.gcwu
AlibabaTrojan:Win32/Emotet.4669eab3
ViRobotTrojan.Win32.Emotet.868352
RisingTrojan.Emotet!1.CB4A (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69819
F-SecureTrojan.TR/Emotet.vbggm
SophosTroj/Emotet-CMG
IkarusTrojan-Banker.Emotet
WebrootW32.Trojan.Gen
AviraTR/Emotet.vbggm
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D110BB
ZoneAlarmTrojan-Banker.Win32.Emotet.gcwu
GDataTrojan.GenericKDZ.69819
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.R349579
VBA32TrojanBanker.Emotet
ALYacTrojan.Agent.Emotet
TACHYONBanker/W32.Emotet.868352.B
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTrojan.MSIL.WACATAC.USXVPHU20
TencentMalware.Win32.Gencirc.10cdf970
FortinetW32/Emotet.CD!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Banker.Win32.Emotet.gcwu?

Trojan-Banker.Win32.Emotet.gcwu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment