Trojan

Trojan.Emotetcrypt information

Malware Removal

The Trojan.Emotetcrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Emotetcrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan.Emotetcrypt?


File Info:

crc32: 8D5EE592
md5: d063affc5ae27421ac211570145736dd
name: upload_file
sha1: 963591cdbd66e839d7eabfc0adad81bdaa62ca68
sha256: 8b64419b900b513275a3484f5df0bfa5cab7adebd0864adde9d1de213bafe19c
sha512: 0cd7293668bb2f2642f91119f7e4232be049a50bc258e35b2eeba3b12758761dc8557496c4a18d414d26a2e8f1b894c6920aa7fabf4746ccc7af17ee8149f076
ssdeep: 6144:zSFpoLPsjOe5Rq2btO4oKAOfK+z32ETjtRPGziL5hzC:yOe5A2gO6arOiL5h+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004
InternalName: SendKeysSample
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: SendKeysSample Application
ProductVersion: 1, 0, 0, 1
FileDescription: SendKeysSample MFC Application
OriginalFilename: SendKeysSample.EXE
Translation: 0x0409 0x04b0

Trojan.Emotetcrypt also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70331
FireEyeGeneric.mg.d063affc5ae27421
CAT-QuickHealTrojan.Emotetcrypt
McAfeeEmotet-FSF!D063AFFC5AE2
CylanceUnsafe
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.70331
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0DIS20
BitDefenderThetaGen:NN.ZexaF.34254.rq0@aiw20obi
CyrenW32/Emotet.ATI.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DIS20
Paloaltogeneric.ml
ClamAVWin.Keylogger.Emotet-9768687-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
AlibabaTrojan:Win32/Emotet.a89b06b3
ViRobotTrojan.Win32.Emotet.278528.B
APEXMalicious
TencentMalware.Win32.Gencirc.10ce060d
Ad-AwareTrojan.GenericKDZ.70331
EmsisoftTrojan.Emotet (A)
ComodoMalware@#30pcji5tcjgwz
F-SecureTrojan.TR/Emotet.otiuz
DrWebTrojan.Emotet.1028
VIPRETrojan.Win32.Generic!BT
InvinceaML/PE-A + Troj/Emotet-CPG
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
SophosTroj/Emotet-CPG
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.ore
MaxSecureTrojan.Malware.11417434.susgen
AviraTR/Emotet.otiuz
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/EmotetCrypt.PEF!MTB
ArcabitTrojan.Generic.D112BB
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataTrojan.GenericKDZ.70331
AhnLab-V3Trojan/Win32.Emotet.C4199851
VBA32BScope.Trojan.Cometer
TACHYONTrojan/W32.Emotet.278528.B
MalwarebytesTrojan.Emotet
PandaTrj/Emotet.C
ESET-NOD32Win32/Emotet.CB
RisingTrojan.Emotet!1.CC99 (CLASSIC)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_90%
FortinetW32/Emotet.EF68!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.095

How to remove Trojan.Emotetcrypt?

Trojan.Emotetcrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment