Trojan

Trojan.Emotet.AIQ (file analysis)

Malware Removal

The Trojan.Emotet.AIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Emotet.AIQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the Emotet malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Emotet.AIQ?


File Info:

name: C09C3FD579632320AF7A.mlw
path: /opt/CAPEv2/storage/binaries/78ba2353743b59861c326cb2ed2cb945826cb8668f99fbf1182e765a8eb95336
crc32: DD5C9F0D
md5: c09c3fd579632320af7aadf93981e549
sha1: 5466d985942606702ac932e6768f9aaccdc43d3c
sha256: 78ba2353743b59861c326cb2ed2cb945826cb8668f99fbf1182e765a8eb95336
sha512: 1067907cfd031c752e399a23ada850c98cb8118fd3387e5f6c453e72c89fb248dace786a3665f388cd0a0b3855edd3d969d90f48ddd8699cdec3e841f20922c6
ssdeep: 12288:mxpXle/CdHI25T6HmRIteIPtdjGemV0dkEu5RVYWfrLReTmxvS6yESRsoo4KUqj:oIaEmWteI1XmV06VRhfrL/a6yESRsoer
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110F46C2137C0C476C27631734516D2B966ADB8319F389B876F941BBD8F786C29E3920E
sha3_384: 133524a154223a79fda49c4663e4de7ba7067feb92fb3454198befd8d4c8aeefd0266b1707bd8ec10857cae886119a0d
ep_bytes: e8e3000100e978feffff6a0c68682f4a
timestamp: 2020-07-28 10:00:47

Version Info:

0: [No Data]

Trojan.Emotet.AIQ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.4!c
AVGWin32:BankerX-gen [Trj]
MicroWorld-eScanTrojan.Emotet.AIQ
FireEyeGeneric.mg.c09c3fd579632320
SkyhighBehavesLike.Win32.Emotet.bh
McAfeeEmotet-FRI!C09C3FD57963
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaBackdoor.Emotet.Win32.649
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056b63c1 )
AlibabaTrojan:Win32/Emotet.2251e0fd
K7GWTrojan ( 0056b63c1 )
BitDefenderThetaGen:NN.ZexaF.36802.UqW@aem4P4cj
VirITTrojan.Win32.Emotet.CIP
SymantecTrojan.Emotet
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HFFU
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Malware.Emotet-9809867-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.Emotet.AIQ
NANO-AntivirusTrojan.Win32.Emotet.hpcpda
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10bd1f21
SophosTroj/Emotet-CKI
F-SecureTrojan.TR/AD.Emotet.HT
DrWebTrojan.DownLoader34.9254
VIPRETrojan.Emotet.AIQ
TrendMicroTrojanSpy.Win32.EMOTET.SMTHO
EmsisoftTrojan.Emotet (A)
JiangminBackdoor.Emotet.ol
VaristW32/Kryptik.BRP.gen!Eldorado
AviraTR/AD.Emotet.HT
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Emotet.AIQ
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.Emotet.AIQ
GoogleDetected
AhnLab-V3Trojan/Win32.Emotet.R346327
VBA32Trojan.Wacatac
ALYacTrojan.Emotet.AIQ
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMTHO
RisingTrojan.Kryptik!1.C71F (CLASSIC)
YandexTrojan.GenKryptik!lnBfmmcicHE
IkarusTrojan-Banker.Agent
FortinetW32/GenKryptik.EPAZ!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Emotet.32a1953d

How to remove Trojan.Emotet.AIQ?

Trojan.Emotet.AIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment