Trojan

Trojan:Win32/Emotet.DHV!MTB removal guide

Malware Removal

The Trojan:Win32/Emotet.DHV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Emotet.DHV!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Saudi Arabia)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r5—sn-4g5e6nl6.gvt1.com

How to determine Trojan:Win32/Emotet.DHV!MTB?


File Info:

crc32: 090B729B
md5: c14cc9772e3b21ca9fede6d6569806bf
name: zel.exe
sha1: 9bc17feeb306933d9a84d636fe833e8e8ed55eac
sha256: 32f75d4a63798dc132ad36560c7cd6447f363f1a4347359dc19f8e71f02aab7f
sha512: cddcbb21080930bd25d1c91924a76cb814ea55ef879d578c03561da8f0c94641dbd9ea9b00a12c844c2d33553860d6b4d5ebf31f1280940f2da316cf456d7821
ssdeep: 12288:veY+nYTjNzKIgYMRiTC1EQErwAroL82UXHRBHNpr6WzfHiNTqOCN4/jSiNJn1hSz:vcnYVgHiTC1ccUXHRBHNpBCzCNsHbnL6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Emotet.DHV!MTB also known as:

DrWebTrojan.Inject3.31182
MicroWorld-eScanTrojan.GenericKD.32769533
McAfeeRDN/Generic.grp
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusTrojan ( 0055c8ac1 )
BitDefenderTrojan.GenericKD.32769533
K7GWTrojan ( 0055c8ac1 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaCO3.32517.3qY@a4P92WmO
SymantecML.Attribute.HighConfidence
GDataTrojan.GenericKD.32769533
KasperskyTrojan-Dropper.Win32.Agent.bjzfnm
Endgamemalicious (high confidence)
SophosMal/Encpk-AOZ
ComodoMalware@#eloka0k672ax
F-SecureTrojan.TR/AD.TrickBot.dbigq
McAfee-GW-EditionRDN/Generic.grp
FireEyeTrojan.GenericKD.32769533
IkarusTrojan-Banker.Emotet
CyrenW32/Trojan.FRAN-3988
WebrootW32.Trojan.Gen
AviraTR/AD.TrickBot.dbigq
ArcabitTrojan.Generic.D1F405FD
ZoneAlarmTrojan-Dropper.Win32.Agent.bjzfnm
MicrosoftTrojan:Win32/Emotet.DHV!MTB
AhnLab-V3Trojan/Win32.Trickbot.C3608303
ALYacTrojan.GenericKD.32769533
MalwarebytesTrojan.TrickBot
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYYO
TrendMicro-HouseCallTROJ_GEN.R011C0PL219
YandexRiskware.BitMiner!
FortinetW32/TrickBot.CJ!tr
Ad-AwareTrojan.GenericKD.32769533
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.501

How to remove Trojan:Win32/Emotet.DHV!MTB?

Trojan:Win32/Emotet.DHV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment