Trojan

Trojan.TaskDisabler.EmGfaeUINsc malicious file

Malware Removal

The Trojan.TaskDisabler.EmGfaeUINsc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.TaskDisabler.EmGfaeUINsc virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan.TaskDisabler.EmGfaeUINsc?


File Info:

name: DCD69755528F5EBB322D.mlw
path: /opt/CAPEv2/storage/binaries/3376a59a0ab5794bf2abd418828479c3f545281fa2ddca2f804bb2bc207d4f49
crc32: B6129F60
md5: dcd69755528f5ebb322dbd21cd0ca6e0
sha1: 6648d3119f784633156a9cd8c089a27d8e09f2cb
sha256: 3376a59a0ab5794bf2abd418828479c3f545281fa2ddca2f804bb2bc207d4f49
sha512: f5127a9dfc539e471f721510d03e0cd0b0106668111828f582bdc7f6b88eaa5aabdc84e2513468fe6fa20e024f7a3df5191557049cc5f6f30b0bf96e52fa6ff1
ssdeep: 12288:GyXVLV5t9xJTMX290RD7BjxBx2ZQUcTG18aaT0OiyjXloS:htVP3JqPx7B06UH8ai
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T192B42399BB9A409ACD65F0BF6C40AD345D18C57CFF8B8501B00A564F7F862A4AF3907E
sha3_384: e340cc64d96a1069ff9746b4c670601fc0a4dec0344bdd199b1442fbe226c7dadfcc67f33bb2b2fe05ac93317d454813
ep_bytes: 60be150041008dbeeb0fffff5789e58d
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan.TaskDisabler.EmGfaeUINsc also known as:

tehtrisGeneric.Malware
ClamAVWin.Malware.Agen-7532797-0
CAT-QuickHealTrojan.WacatacPMF.S16467126
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.19f784
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.BAT.Generic
BitDefenderGen:Trojan.TaskDisabler.EmGfaeUINsc
MicroWorld-eScanGen:Trojan.TaskDisabler.EmGfaeUINsc
TencentMalware.Win32.Gencirc.11bb3c46
Ad-AwareGen:Trojan.TaskDisabler.EmGfaeUINsc
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.gc
FireEyeGeneric.mg.dcd69755528f5ebb
EmsisoftGen:Trojan.TaskDisabler.EmGfaeUINsc (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.TaskDisabler.EmGfaeUINsc
ArcabitTrojan.TaskDisabler.EmGfaeUINsc
Acronissuspicious
ALYacGen:Trojan.TaskDisabler.EmGfaeUINsc
MAXmalware (ai score=85)
CylanceUnsafe
RisingTrojan.Generic@AI.100 (RDMK:cmRtazoirfIxok+nL7g/flNW5fHP)
IkarusTrojan.Win32
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34606.EmGfaeUINsc

How to remove Trojan.TaskDisabler.EmGfaeUINsc?

Trojan.TaskDisabler.EmGfaeUINsc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment