Trojan

Trojan:Win32/Emold!C removal guide

Malware Removal

The Trojan:Win32/Emold!C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Emold!C virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Emold!C?


File Info:

name: 0D5908B1BC2881C7FB6C.mlw
path: /opt/CAPEv2/storage/binaries/9e7727b42f9b61168ccbb8241deee9d6894528a4e299fe671a93984611b58e4c
crc32: DF4A6087
md5: 0d5908b1bc2881c7fb6cd30a48dee64c
sha1: 065645206bb3fb8171e11eabd8b51a17b8085b77
sha256: 9e7727b42f9b61168ccbb8241deee9d6894528a4e299fe671a93984611b58e4c
sha512: 93778de96ae4eecb57fd8a9d7df5886ebd23ed1fb4f244705812857a7e27b30d4cb17266c160c3e412a6a6d39e026441451a31e84d066dbfe4cc178cb49e1374
ssdeep: 768:r6vtVY5DvzcKpIbuVjD55lMRRcmvH57fZ18R3:+v4ZrcswYjzcRh/Vfr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5F2B006B205C10AC68802308917994CE6E4FADE07F656563FE09D7FEDB3197F976E82
sha3_384: 8fd6f7e1e4b65b9ea2b4a332f158e46efc7ff2dc184f2619cc1ba6d7194daf084bb69cb9023b015b6bea64d547275461
ep_bytes: 60be004041008dbe00d0feff5783cdff
timestamp: 2006-12-23 11:18:21

Version Info:

0: [No Data]

Trojan:Win32/Emold!C also known as:

LionicTrojan.Win32.Zbot.l!c
MicroWorld-eScanTrojan.Kobcka.GH
FireEyeGeneric.mg.0d5908b1bc2881c7
McAfeeArtemis!0D5908B1BC28
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.70394
SangforWorm.Win32.AutoRun.YM
K7AntiVirusTrojan ( 0001140e1 )
AlibabaTrojanSpy:Win32/Emold.34edfb20
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.1bc288
BitDefenderThetaGen:NN.ZexaF.34698.cmGfaOKTR6j
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/AutoRun.YM
TrendMicro-HouseCallMal_FrdLoad
Paloaltogeneric.ml
ClamAVWin.Worm.Autorun-9462
KasperskyTrojan-Spy.Win32.Zbot.fnv
BitDefenderTrojan.Kobcka.GH
NANO-AntivirusTrojan.Win32.AutoRun.gpdp
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastFileRepMalware [Trj]
TencentWin32.Trojan-Spy.Zbot.Tnkl
Ad-AwareTrojan.Kobcka.GH
ComodoTrojWare.Win32.Trojan.Katusha.~A@1qgp20
DrWebTrojan.DownLoad.3735
VIPRETrojan.Kobcka.GH
TrendMicroMal_FrdLoad
McAfee-GW-EditionBehavesLike.Win32.Virus.nc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Kobcka.GH (B)
APEXMalicious
GDataTrojan.Kobcka.GH
JiangminWorm/AutoRun.dxj
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Heur.KVM007.a.(kcloud)
ViRobotWorm.Win32.Autorun.37376.H
ZoneAlarmTrojan-Spy.Win32.Zbot.fnv
MicrosoftTrojan:Win32/Emold.gen!C
GoogleDetected
VBA32BScope.Trojan-Dropper.Inject
ALYacTrojan.Kobcka.GH
TACHYONWorm/W32.AutoRun.37376.G
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Win32.Undef.rtv (CLASSIC)
YandexWorm.Autorun.Gen!Pac.10
IkarusPacker.Win32.Katusha
AVGFileRepMalware [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Emold!C?

Trojan:Win32/Emold!C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment