Trojan

What is “Trojan.Emotet.ACZ”?

Malware Removal

The Trojan.Emotet.ACZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Emotet.ACZ virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Emotet.ACZ?


File Info:

crc32: 603C6970
md5: 26aa921d16d9712477e48bfe8a1dae52
name: upload_file
sha1: 2336101d2d8c0bab41e92a365f78a1eee6335794
sha256: 4a3d5d610b577cededbcefad242407edb8849be835c6a0ed6ab8ba335522dd8e
sha512: 85d823e2b2268a6206e034c7d2f7861d13be76a19928a0fe2e38180e247fdac50fd56826c9ba2d91bb8c1403cb67629eff2c7a63c136a7dd200e73769cd2be9b
ssdeep: 1536:QG3AOeY7isrj3XckPBqkM8STvPvIYZ+d0Tdj1SboC9jc:5v7isPXckzSLQYZNhR2c
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Emotet.ACZ also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Emotet.ACZ
FireEyeGeneric.mg.26aa921d16d97124
McAfeeGenericRXIZ-DZ!26AA921D16D9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0053b3091 )
BitDefenderTrojan.Emotet.ACZ
K7GWTrojan ( 0053b3091 )
Cybereasonmalicious.d16d97
TrendMicroTrojanSpy.Win32.EMOTET.DYSGUM
CyrenW32/Emotet.AAZ.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Dropper.Emotet-7414830-0
KasperskyHEUR:Backdoor.Win32.Gulpix.gen
AlibabaBackdoor:Win32/Emotet.932c5d00
NANO-AntivirusVirus.Win32.Gen.ccmw
AegisLabTrojan.Win32.Gulpix.m!c
RisingTrojan.Emotet!1.BDEC (CLASSIC)
Ad-AwareTrojan.Emotet.ACZ
SophosMal/Emotet-N
ComodoMalware@#26y31lbrwvbp2
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Emotet.762
ZillyaTrojan.Emotet.Win32.18888
InvinceaML/PE-A + Mal/Emotet-N
McAfee-GW-EditionBehavesLike.Win32.Generic.qh
EmsisoftTrojan.Emotet.ACZ (B)
IkarusTrojan-Banker.Emotet
JiangminBackdoor.Gulpix.rt
eGambitUnsafe.AI_Score_72%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan[Backdoor]/Win32.Gulpix
MicrosoftTrojan:Win32/Emotet.DHF!MTB
ArcabitTrojan.Emotet.ACZ
ZoneAlarmHEUR:Backdoor.Win32.Gulpix.gen
GDataWin32.Trojan.Kryptik.NZ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R292337
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34254.duX@a4UXSxb
ALYacTrojan.Emotet.ACZ
VBA32BScope.Trojan.Dovs
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Emotet.BN
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.DYSGUM
TencentWin32.Backdoor.Gulpix.Hrze
YandexTrojan.Emotet!
SentinelOneDFI – Malicious PE
FortinetW32/Generic.AP.2E66E8!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.3a0

How to remove Trojan.Emotet.ACZ?

Trojan.Emotet.ACZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment