Trojan

Trojan.Emotet.ALY removal tips

Malware Removal

The Trojan.Emotet.ALY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Emotet.ALY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

How to determine Trojan.Emotet.ALY?


File Info:

crc32: D76E09C7
md5: d74b9f6830023520771cbc0bbb8b2c32
name: upload_file
sha1: 7cfb4d200b8b5d36c2d675787e9880afec17cafb
sha256: d8cc8369defb65bc690d0a99e15762f6c8aa7574035fa176446541b32ab6a502
sha512: 1692c2279398f71d5b9b6663610ebf6b01794b94d1ba43b6bddacc7eef27a21ad61a61a10fc4a650ee9e3d0ac2469a3168dc478905053f774626244170a15fc9
ssdeep: 6144:rQLW0DePDxi/egYSvEOSxlAxD/lsnl3r:rQL7qrxKixlABelb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004
InternalName: SendKeysSample
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: SendKeysSample Application
ProductVersion: 1, 0, 0, 1
FileDescription: SendKeysSample MFC Application
OriginalFilename: SendKeysSample.EXE
Translation: 0x0409 0x04b0

Trojan.Emotet.ALY also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Emotet.1028
MicroWorld-eScanTrojan.Emotet.ALY
FireEyeTrojan.Emotet.ALY
ALYacTrojan.Agent.Emotet
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005605291 )
BitDefenderTrojan.Emotet.ALY
K7GWTrojan ( 005605291 )
BitDefenderThetaGen:NN.Zextet.34254.nq0@aG0508gi
CyrenW32/Emotet.ATI.gen!Eldorado
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
AlibabaTrojan:Win32/Emotet.c8048b11
ViRobotTrojan.Win32.Emotet.225280.B
TencentWin32.Trojan-banker.Emotet.Wqmt
Ad-AwareTrojan.Emotet.ALY
SophosTroj/Emotet-CPC
InvinceaMal/Generic-S + Troj/Emotet-CPC
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
EmsisoftTrojan.Emotet (A)
AviraTR/Emotet.vjyxs
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Emotet.ALY
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataWin32.Trojan-Spy.Emotet.ECFX35
AhnLab-V3Trojan/Win32.Emotet.R352092
McAfeeEmotet-FSF!D74B9F683002
VBA32BScope.Trojan.Zenpak
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CI
TrendMicro-HouseCallTROJ_GEN.R002H06IO20
RisingTrojan.Generic@ML.97 (RDML:P2RHQ/HJeQN69F7SKaE9EA)
IkarusTrojan-Banker.Emotet
FortinetW32/Emotet.1028!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.Emotet.ALY?

Trojan.Emotet.ALY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment