Trojan

Trojan.EmotePMF.S15541450 malicious file

Malware Removal

The Trojan.EmotePMF.S15541450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.EmotePMF.S15541450 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.EmotePMF.S15541450?


File Info:

crc32: C13044A1
md5: efac7cb05574bd6682510da1556d413e
name: upload_file
sha1: b893d32043edbaf45b9a70db0a67d28ff3f05e43
sha256: 45a0e34a97ac839f5fbf8b8e48e9b8a623e87a7f37000fda3192581e8202d444
sha512: 7df3f43fc5f0a4103a24fc026a4c56cbcfbfa16abfa16e5d974784e1f92451830b5ed43ffb7ae5f0a82cd1df3c5eb859109064590ea483c0b4aac0bbca8136db
ssdeep: 6144:1LHsfMZz0e/aVq6XX4jYDRbqzN7u/mHYzPccld5b2IOIQlNtGZknCvuVbo:1jsMAe/aVdXXsYFbqp7dPJVM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006
InternalName: oscilloscope
FileVersion: 2, 0, 0, 0
CompanyName: Waikato University
PrivateBuild:
LegalTrademarks:
Comments: Modified by Cyril COMTE
ProductName: Waikato University oscilloscope-compressor
SpecialBuild:
ProductVersion: 2, 0, 0, 0
FileDescription: oscilloscope-compressor
OriginalFilename: oscilloscope.exe->compressor
Translation: 0x1409 0x04b0

Trojan.EmotePMF.S15541450 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69658
FireEyeTrojan.GenericKDZ.69658
CAT-QuickHealTrojan.EmotePMF.S15541450
Qihoo-360Win32/Backdoor.9b6
ALYacTrojan.GenericKDZ.69658
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69658
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0DHN20
CyrenW32/Emotet.AQV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyBackdoor.Win32.Emotet.cjry
AlibabaTrojan:Win32/Emotet.640ce1c3
NANO-AntivirusTrojan.Win32.Emotet.hrygxr
AegisLabTrojan.Win32.Emotet.L!c
TencentMalware.Win32.Gencirc.10cdec3d
Ad-AwareTrojan.GenericKDZ.69658
F-SecureTrojan.TR/Emotet.whnwb
DrWebTrojan.Emotet.1004
ZillyaTrojan.Emotet.Win32.24756
InvinceaMal/Generic-R + Troj/Emotet-CLO
SophosTroj/Emotet-CLO
JiangminBackdoor.Emotet.sm
AviraTR/Emotet.whnwb
MAXmalware (ai score=82)
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D1101A
ZoneAlarmBackdoor.Win32.Emotet.cjry
GDataTrojan.GenericKDZ.69658
AhnLab-V3Malware/Win32.Generic.C4185182
McAfeeEmotet-FRV!EFAC7CB05574
TACHYONTrojan/W32.Agent.374272.JT
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMTHH.hp
RisingTrojan.Kryptik!1.CAF3 (CLASSIC)
YandexTrojan.Emotet!
IkarusTrojan-Banker.Emotet
FortinetW32/Emotet.F4A9!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.105895046.susgen

How to remove Trojan.EmotePMF.S15541450?

Trojan.EmotePMF.S15541450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment