Trojan

Trojan.EmotePMF.S16487402 removal instruction

Malware Removal

The Trojan.EmotePMF.S16487402 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.EmotePMF.S16487402 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r4—sn-4g5e6nzs.gvt1.com

How to determine Trojan.EmotePMF.S16487402?


File Info:

crc32: 22EC1C2B
md5: af385c1bb33726b74852c36b1e38ee63
name: AF385C1BB33726B74852C36B1E38EE63.mlw
sha1: 8558bb46eae13834d8f6b4fffd1927f981af42ae
sha256: 00d6ac52a2e0c93dd5f0cfa300788b96d499fca2d45125f5ae57a9f137fe8aa8
sha512: 471d308ed3120d07cab7d1f5704d3e48a014d76e6cc182b8951c68c263c47e382194f4624987a9dfce822d2f38393d45b4b29cf8b9ac7247c4e559e09959de82
ssdeep: 6144:QWXIwVZNNuh5pVI7Lf36g3uLcxjmkovvLg+4wnS9+RR1eis3f1k:PNE5pVI7z36g3uIxjmhvvxnY+71Xge
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) Copyright 2006 by Steffen Lange
InternalName: PwdChange.exe
FileVersion: 1.0.0.1
CompanyName: Steffen Lange
LegalTrademarks: Alle Rechte vorbehalten.
ProductName: Password Changer
ProductVersion: 1.0.0.1
FileDescription: Password Changer
OriginalFilename: PwdChange.exe
Translation: 0x0407 0x04e4

Trojan.EmotePMF.S16487402 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.Ranapama.AMW
FireEyeTrojan.Ranapama.AMW
CAT-QuickHealTrojan.EmotePMF.S16487402
Qihoo-360Win32/Trojan.ffa
ALYacTrojan.Ranapama.AMW
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zenpak.4!c
K7AntiVirusTrojan ( 0056efc81 )
BitDefenderTrojan.Ranapama.AMW
K7GWTrojan ( 0056efc81 )
TrendMicroTrojanSpy.Win32.EMOTET.THKAGBO
CyrenW32/Emotet.AVA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9778932-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
AlibabaTrojan:Win32/EmotetCrypt.766b35b5
NANO-AntivirusTrojan.Win32.Emotet.hzryrf
ViRobotTrojan.Win32.Z.Emotet.369664.AD
Ad-AwareTrojan.Ranapama.AMW
SophosTroj/Emotet-CQX
ComodoMalware@#30avpu2zxlc5a
F-SecureTrojan.TR/AD.Emotet.pdjej
DrWebTrojan.Emotet.1042
ZillyaTrojan.Emotet.Win32.43766
InvinceaMal/Generic-R + Troj/Emotet-CQX
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.oyd
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.pdjej
Antiy-AVLTrojan/Win32.Emotet
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.Ranapama.AMW
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
GDataTrojan.Ranapama.AMW
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4206910
McAfeeEmotet-FSF!AF385C1BB337
MAXmalware (ai score=84)
VBA32Trojan.Zenpak
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CI
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THKAGBO
RisingTrojan.Emotet!1.CD65 (CLASSIC)
YandexTrojan.GenKryptik!fDuaOfgHIA8
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HEOE!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.EmotePMF.S16487402?

Trojan.EmotePMF.S16487402 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment