Trojan

What is “Trojan-Banker.Win32.Emotet.gdnw”?

Malware Removal

The Trojan-Banker.Win32.Emotet.gdnw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Emotet.gdnw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.Emotet.gdnw?


File Info:

crc32: 0E28167B
md5: e480a05b02f1deabe2cc1feac855a2d7
name: upload_file
sha1: 42897a862c021067e652a2d2b44fd4effe31e323
sha256: c2080c75aa83d0f79980fd57a6f828d35b9f85461bf47c5e01bee28839c4c1bf
sha512: b43ddba34973d1b1d78c613c3e93ac5b6e0703f1c49a06fa21d4de385c5f6abb1f550528ab5325e4d9d04b6fa8b3c9f2f5d726240add71ac980ec05be7861da1
ssdeep: 6144:9BZ2wMIvZsPPiNmauX3ZzHi1HHxTg3VOYqn2suETCO2QA+xJX7G:p6Pigji1HHtgfPsu8J/i
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Free to redistribute!
InternalName: cmdcmxcfg.exe
FileVersion: 1.0.0.1
CompanyName: Shaun Harrington
ProductName: CMDCMX
ProductVersion: 1.0.0.1
FileDescription: CMDCMX Configuration Application
OriginalFilename: cmdcmxcfg.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.Emotet.gdnw also known as:

BkavW32.VobfusAgentHAA.Trojan
MicroWorld-eScanTrojan.GenericKD.34520348
FireEyeTrojan.GenericKD.34520348
CAT-QuickHealTrojan.EmotetPMF.S15717669
McAfeeEmotet-FSD!E480A05B02F1
MalwarebytesTrojan.Emotet
ZillyaTrojan.Emotet.Win32.28381
AegisLabTrojan.Win32.Emotet.truJ
SangforMalware
K7AntiVirusTrojan ( 0056dcf11 )
BitDefenderTrojan.GenericKD.34520348
K7GWTrojan ( 0056dcf11 )
TrendMicroTROJ_GEN.R002C0DI720
BitDefenderThetaGen:NN.ZexaF.34254.uq0@ai@0Bkci
CyrenW32/Kryptik.BWJ.gen!Eldorado
SymantecTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HFZC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Emotet-9753021-0
KasperskyTrojan-Banker.Win32.Emotet.gdnw
AlibabaTrojan:Win32/Emotet.16630cec
NANO-AntivirusTrojan.Win32.Emotet.huenpd
ViRobotTrojan.Win32.Emotet.334848.A
RisingTrojan.Emotet!1.CBD1 (CLASSIC)
Ad-AwareTrojan.GenericKD.34520348
SophosTroj/Emotet-CLZ
DrWebTrojan.Emotet.1016
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Emotet-CLZ
McAfee-GW-EditionBehavesLike.Win32.Emotet.fh
EmsisoftTrojan.Emotet (A)
JiangminTrojan.Banker.Emotet.oih
MaxSecureTrojan.Malware.106378930.susgen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D20EBD1C
AhnLab-V3Malware/Win32.Generic.C4192704
ZoneAlarmTrojan-Banker.Win32.Emotet.gdnw
GDataTrojan.GenericKD.34520348
VBA32TrojanBanker.Emotet
ALYacTrojan.Agent.Emotet
TACHYONBanker/W32.Emotet.334848
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DI720
TencentMalware.Win32.Gencirc.10cdfdc6
IkarusTrojan-Banker.Emotet
FortinetW32/Kryptik.HFZC!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.C2B1.Malware.Gen

How to remove Trojan-Banker.Win32.Emotet.gdnw?

Trojan-Banker.Win32.Emotet.gdnw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment