Trojan

Should I remove “Trojan:Win32/Emotet.PBB!MTB”?

Malware Removal

The Trojan:Win32/Emotet.PBB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Emotet.PBB!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Emotet.PBB!MTB?


File Info:

crc32: D18676C6
md5: fc0a04c3c2f4511e74a2db2b754cf0ac
name: upload_file
sha1: 54f05d4a62d7d36e483ebc5a7dda7ca56c9d14d9
sha256: d1a92dd5597780d2ea2a2b9220cc202c8213f6d9ee4af91725536d71071dc6ef
sha512: eff052506f773cd52924be175befb4268333577fd06b0b6436e5d477131071ffd38a9edb1514c0da18411faa3f14a51e3cc7c2ea82e6ab0b88aad622a49366ee
ssdeep: 6144:Pj02cdBGkACWMdawLM8u3fD/FIjcv0cnSweFTwW48:P4bu98ufrFIjcLVeFTw
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Emotet.PBB!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34399780
FireEyeGeneric.mg.fc0a04c3c2f4511e
BitDefenderTrojan.GenericKD.34399780
CrowdStrikewin/malicious_confidence_60% (D)
APEXMalicious
KasperskyTrojan.Win32.Zenpak.aubs
Ad-AwareTrojan.GenericKD.34399780
MicrosoftTrojan:Win32/Emotet.PBB!MTB
ArcabitTrojan.Generic.D20CE624
ZoneAlarmTrojan.Win32.Zenpak.aubs
GDataTrojan.GenericKD.34399780
ESET-NOD32Win32/TrickBot.DG
ALYacTrojan.GenericKD.34399780
MAXmalware (ai score=85)
PandaTrj/GdSda.A

How to remove Trojan:Win32/Emotet.PBB!MTB?

Trojan:Win32/Emotet.PBB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment