Trojan

Should I remove “Trojan.Emotet.AGZ”?

Malware Removal

The Trojan.Emotet.AGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Emotet.AGZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Created a service that was not started

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Emotet.AGZ?


File Info:

crc32: C825809D
md5: ca9cb2fa29be611cd6c85e70a5ffe004
name: CA9CB2FA29BE611CD6C85E70A5FFE004.mlw
sha1: bc03fd9a7855b3ca49e7968cf0274f2fefc152cd
sha256: c2789174baccf91d9e286c827a260766e7a7e064098d9d93acbd400dea4099dc
sha512: 2f69c31f9e304b43d819fffe57ff4ee5c4154842d0957a24f0c41ea518afc560efa88cadf57b9a282e27d54654fb859ab8ecbad7bd357c558b42acf96b1253cc
ssdeep: 6144:FcrEgl/Si74QFaT6lXhQyo7ilSHM2SAHHAkSs8pxeIBcB47pJfa:F8EsH74QaT6lRc7ilsMdWgE8HeIBv7pQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2004
InternalName: EliteConverter
FileVersion: 1, 0, 0, 1
CompanyName: hAx Studios Ltd.
PrivateBuild: EliteDecoder
LegalTrademarks: hAx Studios Ltd., Root-hack, fritz
Comments: Elite Character Conversion by: http://hax-studios.net && http://root-hack.org || fritzy
ProductName: EliteConv Application
SpecialBuild: Converter
ProductVersion: 1, 0, 0, 1
FileDescription: Elite Converter | hex, dec, bin, oct and ascii
OriginalFilename: EliteConv.EXE
Translation: 0x0409 0x04b0

Trojan.Emotet.AGZ also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Emotet.AGZ
FireEyeGeneric.mg.ca9cb2fa29be611c
McAfeeGenericRXAA-AA!CA9CB2FA29BE
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
K7AntiVirusTrojan ( 0056078d1 )
BitDefenderTrojan.Emotet.AGZ
K7GWTrojan ( 0056078d1 )
TrendMicroTrojanSpy.Win32.EMOTET.SML.hp
CyrenW32/Emotet.AHK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Emotet-7585722-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
NANO-AntivirusTrojan.Win32.Emotet.hbbrpy
Ad-AwareTrojan.Emotet.AGZ
SophosMal/EncPk-API
F-SecureHeuristic.HEUR/AGEN.1125667
DrWebTrojan.Emotet.915
InvinceaMal/EncPk-API
McAfee-GW-EditionEmotet-FOT!2AD21D2EB934
EmsisoftTrojan.Emotet.AGZ (B)
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.elixu
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1125667
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
GridinsoftTrojan.Win32.Kryptik.ka!n
ArcabitTrojan.Emotet.AGZ
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataTrojan.Emotet.AGZ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3981298
VBA32BScope.Trojan.Detplock
MAXmalware (ai score=80)
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HBAZ
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SML.hp
YandexTrojan.GenAsa!L85XJZcZ7Bk
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HBGW!tr
BitDefenderThetaGen:NN.ZexaE.34634.umLfa8e0xsbi
AVGWin32:TrojanX-gen [Trj]
Qihoo-360HEUR/QVM19.1.3A86.Malware.Gen

How to remove Trojan.Emotet.AGZ?

Trojan.Emotet.AGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment