Trojan

Should I remove “Trojan:Win32/Emotet.RBA!MTB”?

Malware Removal

The Trojan:Win32/Emotet.RBA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Emotet.RBA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Emotet.RBA!MTB?


File Info:

crc32: 0A6448E4
md5: 1bc602b53eb408610e7a67dec2313072
name: upload_file
sha1: 0df12881cb0c4049a547b642c2652ca01873224b
sha256: 1beb2231101436ee5c55060884e48f6e72c17ccb9a47466f2d3ec7e4f5c585bb
sha512: 14b5a5790bbb9876f1d980b188d46b7422365ea837065b8e6b685602a525556f67058d86f37f91763ece2c920c472ce12eecfd03a5f7797ad3e9607913082ca9
ssdeep: 768:CMZxWk/4D6acfuU4/PaxqsgoJ62Rk0oWKFrYR35Mh5jRuoRL:CML/favfsLQ2O0UY5kj
type: MS-DOS executable

Version Info:

0: [No Data]

Trojan:Win32/Emotet.RBA!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Emotet.X.E1201A95
FireEyeGeneric.mg.1bc602b53eb40861
CAT-QuickHealBackdoor.Emotet
McAfeeGenericRXJR-JC!1BC602B53EB4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005600261 )
BitDefenderDeepScan:Generic.Emotet.X.E1201A95
K7GWTrojan ( 005600261 )
Cybereasonmalicious.53eb40
InvinceaMal/Generic-S
BitDefenderThetaAI:Packer.DC3FA1291E
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallCryp_Xin1
KasperskyHEUR:Backdoor.Win32.Emotet.vho
AlibabaTrojan:Win32/Emotet.9fd6e4ae
NANO-AntivirusVirus.Win32.Gen.ccmw
APEXMalicious
TencentWin32.Backdoor.Emotet.Ebri
Ad-AwareDeepScan:Generic.Emotet.X.E1201A95
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1136848
DrWebTrojan.Emotet.999
ZillyaBackdoor.Emotet.Win32.1136
TrendMicroCryp_Xin1
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1136848
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Emotet.RBA!MTB
ArcabitDeepScan:Generic.Emotet.X.E1201A95
ZoneAlarmHEUR:Backdoor.Win32.Emotet.vho
GDataDeepScan:Generic.Emotet.X.E1201A95
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Emotet.C4184986
VBA32Backdoor.Emotet
ALYacDeepScan:Generic.Emotet.X.E1201A95
AvastWin32:Trojan-gen
ESET-NOD32a variant of Win32/Kryptik.BEP
RisingTrojan.Emotet!1.CAB7 (CLASSIC)
YandexTrojan.Emotet!
SentinelOneDFI – Malicious PE
FortinetW32/Emotet.CD!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.101

How to remove Trojan:Win32/Emotet.RBA!MTB?

Trojan:Win32/Emotet.RBA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment