Trojan

What is “Trojan-Banker.Win32.Emotet.gdmm”?

Malware Removal

The Trojan-Banker.Win32.Emotet.gdmm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gdmm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Romanian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.Emotet.gdmm?


File Info:

crc32: AF120101
md5: c2fda0658bb8b4a596bc7e6b2a7a4578
name: upload_file
sha1: 8fcf489e2a13f87ae36741e2a5021348a851d54f
sha256: c1c400ee244930189edd44fea81b66045524df356fa8533fa101b087b9ecdbc4
sha512: b36d08650c40298c3877156369bd08d2751d116dab9c6e19968125c7724a38166c9130fe2f0e2d27ea7404deb2a29c228b3ccb2a72fc4931dcf70da016c64d47
ssdeep: 6144:nz26ALg+dVQM0IIP33gSeKzO4eHp0G5EbnzQCokkUCPOjI+lTcM:r80Io33QKzO4emVbnzQCokkUCPOUDM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Force base from his rally on Thursday night.
InternalName: Trump again said mail-in ballots are a.exe
FileVersion: 660.7.9
CompanyName: here have been many weeks when the Trump train
ProductName: As well as the North Carolina furor
ProductVersion: 5.99.34.1
FileDescription: The outrages, conspiracy theories and drama have come so fast>
OriginalFilename: Trump will ignite a new uproar soon enough.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.Emotet.gdmm also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69915
FireEyeGeneric.mg.c2fda0658bb8b4a5
McAfeeEmotet-FSC!C2FDA0658BB8
CylanceUnsafe
K7AntiVirusTrojan ( 0056dc3b1 )
BitDefenderTrojan.GenericKDZ.69915
K7GWTrojan ( 0056dc3b1 )
CyrenW32/Kryptik.BWK.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Emotet-9753169-0
KasperskyTrojan-Banker.Win32.Emotet.gdmm
NANO-AntivirusTrojan.Win32.Emotet.hubynz
RisingTrojan.Emotet!1.CBDE (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69915
SophosTroj/Emotet-CNA
DrWebTrojan.DownLoader34.32516
ZillyaTrojan.Emotet.Win32.28376
InvinceaML/PE-A + Troj/Emotet-CNA
McAfee-GW-EditionBehavesLike.Win32.Emotet.gh
EmsisoftTrojan.GenericKDZ.69915 (B)
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.ohv
AviraHEUR/AGEN.1138190
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D1111B
ZoneAlarmTrojan-Banker.Win32.Emotet.gdmm
GDataTrojan.GenericKDZ.69915
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R350747
VBA32TrojanBanker.Emotet
ALYacTrojan.Agent.Emotet
TACHYONBanker/W32.Emotet.458752.L
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HFYL
TencentMalware.Win32.Gencirc.10cdfdbd
FortinetW32/emotet.55C3!tr
BitDefenderThetaGen:NN.ZexaF.34570.Cq0@aW0KSAdO
AVGWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.Emotet.gdmm?

Trojan-Banker.Win32.Emotet.gdmm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment