Trojan

How to remove “Trojan:Win32/Emotet.D”?

Malware Removal

The Trojan:Win32/Emotet.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Emotet.D virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Trojan:Win32/Emotet.D?


File Info:

name: D7FD49D4410382601FE6.mlw
path: /opt/CAPEv2/storage/binaries/734d09cbc840e4349a3d5fd4751e2237d7cc5066590cd0408e2cfad354fd4c38
crc32: 9A82B494
md5: d7fd49d4410382601fe67202e8c1a79c
sha1: 535a451840798c318ce47dbcc3dd2a44ee2fa547
sha256: 734d09cbc840e4349a3d5fd4751e2237d7cc5066590cd0408e2cfad354fd4c38
sha512: 83201380e91f4b8b6a3e3f57272717651842fe480a3c92c64289ec695e83e49abad633bdba0436886e89c90b6a9c4489ba0dc3236762b2f3598c4ed54c9037c4
ssdeep: 3072:9NEZWOQdDuZph4fWy6c3v40y+rzqVCr+YARsI6u2t4Y9sBG0hac0v2DEoro+:9cKNuFIdt3vTrz1r+R7F2t4pUOEoB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6145C5133E86D11F1618F340573D6429EADBDA28E73D18EB6C03D9F083AAC4AE39756
sha3_384: 4fe108fd1dbe926ef30b68acf732b6afdfa40473e5b112027d45b2cdd48f24f3b5c899a3a9367cdcd4a9bec940abfb9d
ep_bytes: c82c00005653572bff681c594000ff35
timestamp: 2014-09-29 12:47:36

Version Info:

CompanyName: Pigmenting Chymosin
FileDescription: scuppering leugh oke
FileVersion: 7.7.7109.30110
InternalName: scuppering
LegalCopyright: Copyright Pigmenting Chymosin
OriginalFilename: scuppering.exe
ProductName: scuppering einsteinium
ProductVersion: 7.7.7109.30110
Translation: 0x0409 0x04b0

Trojan:Win32/Emotet.D also known as:

LionicTrojan.Win32.Emotet.L!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AgentWDCR.CPW
FireEyeGeneric.mg.d7fd49d441038260
SkyhighGeneric.vd
McAfeeGeneric.vd
Cylanceunsafe
ZillyaBackdoor.Hupigon.Win32.187243
SangforSpyware.Win32.Emotet.Vnly
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Emotet.46c703cc
K7GWTrojan ( 004b11851 )
K7AntiVirusTrojan ( 004b11851 )
ArcabitTrojan.AgentWDCR.CPW
BitDefenderThetaGen:NN.ZexaF.36744.my0@aqnecHci
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Emotet.AB
ZonerTrojan.Win32.27335
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Hupigon.tgzm
BitDefenderTrojan.AgentWDCR.CPW
NANO-AntivirusTrojan.Win32.Hupigon.efhgif
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13d31bea
TACHYONBackdoor/W32.Hupigon.200704.V
EmsisoftTrojan.AgentWDCR.CPW (B)
F-SecureTrojan.TR/Crypt.XPACK.104154
DrWebTrojan.Emotet.50
VIPRETrojan.AgentWDCR.CPW
TrendMicroTROJ_EMOTET.WJSW
SophosMal/Generic-S
IkarusTrojan-Spy.Zbot
JiangminBackdoor/Hupigon.codl
WebrootTrojan.Dropper.Gen
VaristW32/Trojan.NISB-1741
AviraTR/Crypt.XPACK.104154
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Hack.Huigezi.tgzm
XcitiumMalware@#2qxxd0jjlobcb
MicrosoftTrojan:Win32/Emotet.D
ZoneAlarmBackdoor.Win32.Hupigon.tgzm
GDataWin32.Trojan.Agent.0CRACM
GoogleDetected
ALYacTrojan.Agent.Emotet
MAXmalware (ai score=100)
VBA32Backdoor.Hupigon
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/WLT.B
TrendMicro-HouseCallTROJ_EMOTET.WJSW
RisingBackdoor.Win32.Kasido.i (CLASSIC)
YandexBackdoor.Hupigon!rEPrjRfpaJg
MaxSecureTrojan.Malware.7934072.susgen
FortinetW32/Emotet.AB!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Emotet.D?

Trojan:Win32/Emotet.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment