Trojan

Trojan-Banker.Win32.Emotet.gdbp removal

Malware Removal

The Trojan-Banker.Win32.Emotet.gdbp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gdbp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

How to determine Trojan-Banker.Win32.Emotet.gdbp?


File Info:

crc32: 3A99F063
md5: 853b91327b24d3ee26a5ad4a9cbd8f0b
name: upload_file
sha1: 2926e21a8cef7b178580705b0c9bc4f2109f5905
sha256: 11bd224460e2970850b6452697e7f819d2a0ba785fe81af0674350d1df6494e9
sha512: 1c522af22c0ae64ef079b2f0822d0579eb2ea0c9bcb3691310742615c403ca167593219fda835f746b9dda3e4192e33f1b18a7af37ab899ccaef2f6bca1f66ff
ssdeep: 6144:Mpe63b5W9ALT/5+VxdMEW4UCXSGFHSrV2D6kWPzn8RVYrz1Sc+/:ce6LsScVnMX4UCBFHFD6kWPz8RmSr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ButtonEx
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Anwendung ButtonEx
ProductVersion: 1, 0, 0, 1
FileDescription: MFC-Anwendung ButtonEx
OriginalFilename: ButtonEx.EXE
Translation: 0x0407 0x04b0

Trojan-Banker.Win32.Emotet.gdbp also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69847
FireEyeTrojan.GenericKDZ.69847
CAT-QuickHealTrojan.GenericRI.S15761361
McAfeeEmotet-FRZ!853B91327B24
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0053af701 )
BitDefenderTrojan.GenericKDZ.69847
K7GWTrojan ( 0053af701 )
TrendMicroTROJ_GEN.R002C0DI320
CyrenW32/Emotet.ARR.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Emotet-9628825-0
KasperskyTrojan-Banker.Win32.Emotet.gdbp
AlibabaTrojan:Win32/Emotet.47c2dfa9
NANO-AntivirusTrojan.Win32.Emotet.htqmjj
ViRobotTrojan.Win32.Emotet.507904.E
AegisLabTrojan.Win32.Emotet.L!c
RisingTrojan.Kryptik!1.CB94 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69847
SophosTroj/Emotet-CMU
F-SecureTrojan.TR/AD.Emotet.hfyvf
DrWebTrojan.Emotet.1008
ZillyaTrojan.Emotet.Win32.28063
InvinceaMal/Generic-R + Troj/Emotet-CMU
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
EmsisoftTrojan.Emotet (A)
JiangminTrojan.Banker.Emotet.ogu
MaxSecureTrojan.Malware.106184236.susgen
AviraTR/AD.Emotet.hfyvf
MAXmalware (ai score=80)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D110D7
ZoneAlarmTrojan-Banker.Win32.Emotet.gdbp
GDataWin32.Trojan.PSE.VZZZ2W
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R350034
ALYacTrojan.Agent.Emotet
TACHYONBanker/W32.Emotet.508002
VBA32BScope.Trojan.MulDrop
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R002C0DI320
TencentMalware.Win32.Gencirc.10cdfc46
YandexTrojan.Kryptik!3U+txq8nmc0
IkarusTrojan-Banker.Emotet
FortinetPossibleThreat.MU
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.9b3

How to remove Trojan-Banker.Win32.Emotet.gdbp?

Trojan-Banker.Win32.Emotet.gdbp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment