Trojan

Should I remove “Trojan.Emotet.ANS”?

Malware Removal

The Trojan.Emotet.ANS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Emotet.ANS virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs

How to determine Trojan.Emotet.ANS?


File Info:

crc32: 69E8889E
md5: 4f134d35f7d1afe6c91085f38e27640d
name: 4F134D35F7D1AFE6C91085F38E27640D.mlw
sha1: 0102f545e6b8acefaff628159cd06697d9c520b7
sha256: b73bae190d2c8d18cbf00584c496e4f570da582507dbdbacdc8893053e5996ae
sha512: 3bd09ea9b443fce5c9f78430b9e7254513907be81751ee671a133f7d2c46ad17c868fcdb5d382ee3a8cf4d2b931f5b07c2d86b52dea9f75b5dfa722b12c4abb9
ssdeep: 3072:FW3jihpPN6334j29ujis6fyMhzEeSOTDAUnDAVnNrRV+BwrLcqfQD4YGpw/pCn:Y3j8pPN6n4j7Ws61E+ABnF/cl0pwwn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: wmprph.exe
FileVersion: 12.0.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 12.0.7600.16385
FileDescription: Windows Media Player Rich Preview Handler
OriginalFilename: wmprph.exe
Translation: 0x0409 0x04b0

Trojan.Emotet.ANS also known as:

Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.1031
CynetMalicious (score: 100)
CAT-QuickHealTrojan.QshellPMF.S18197934
ALYacTrojan.Agent.ZLoader
CylanceUnsafe
ZillyaDownloader.Zload.Win32.167
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Zload.5faec3d3
K7GWTrojan ( 005761161 )
K7AntiVirusTrojan ( 005761161 )
CyrenW32/Trojan.AXXM-6743
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HISZ
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Packed.Qshell-9820629-0
KasperskyHEUR:Trojan-Downloader.Win32.Zload.vho
BitDefenderTrojan.Emotet.ANS
ViRobotTrojan.Win32.Zloader.313688
MicroWorld-eScanTrojan.Emotet.ANS
Ad-AwareTrojan.Emotet.ANS
SophosMal/Generic-S
ComodoMalware@#kqkvqpkyjkmo
BitDefenderThetaGen:NN.ZedlaF.34738.tu9@a0eCnigi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0DFF21
McAfee-GW-EditionZloader-FTGW!4F134D35F7D1
FireEyeGeneric.mg.4f134d35f7d1afe6
EmsisoftTrojan.Emotet.ANS (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Zload.ga
WebrootW32.Trojan.Emotet
AviraTR/SpyBot.ysgps
Antiy-AVLTrojan/Generic.ASCommon.1BE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Zloader.GA!MTB
ArcabitTrojan.Emotet.ANS
AegisLabTrojan.Win32.Zload.a!c
ZoneAlarmHEUR:Trojan-Downloader.Win32.Zload.vho
GDataTrojan.Emotet.ANS
AhnLab-V3Trojan/Win32.RL_Bunitu.R362784
McAfeeZloader-FTGW!4F134D35F7D1
MAXmalware (ai score=86)
VBA32Trojan.SpyBot
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CC0DFF21
YandexTrojan.DL.Zload!arYQRVxvH/k
IkarusTrojan.Win32.Generic
MaxSecureDownloader.Downloader.WIN32.Zload.pef.010221_210469
FortinetW32/Kryptik.HIZF!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Trojan.Emotet.ANS?

Trojan.Emotet.ANS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment