Backdoor

Backdoor.Win32.Emotet.ahie malicious file

Malware Removal

The Backdoor.Win32.Emotet.ahie is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.ahie virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.ahie?


File Info:

crc32: B21F422A
md5: 9a5d68e510f4925706f93a13332b0c2b
name: upload_file
sha1: 80de712bbc4a32876a241b7b37d1dd02b4ebcf74
sha256: ea45e0dedf1008723e61d8a413b47a6f0f1a2dc3e8be9f03107f7b28994efcbe
sha512: 213907241e1f06b534656ad9e7c088847722e1acfdfe05d6e797cd6ff0a01cea32fdb4c1a12eb3f3fc34a374043a8b52c6d306a440f09d884f643b9fa8acf8af
ssdeep: 12288:M2NVqHzevfqCG8pInsjtoXejRnBMm8y3H:M2KWfqmpI+oypb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: CHexEditDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CHexEditDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: CHexEditDemo MFC Application
OriginalFilename: CHexEditDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.ahie also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EUFR
FireEyeGeneric.mg.9a5d68e510f49257
McAfeeEmotet-FRI!9A5D68E510F4
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusTrojan ( 0056b6ba1 )
BitDefenderTrojan.Agent.EUFR
K7GWTrojan ( 0056b6ba1 )
Invinceaheuristic
F-ProtW32/Emotet.AOD.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyBackdoor.Win32.Emotet.ahie
AlibabaTrojan:Win32/Emotet.2a39bdef
ViRobotTrojan.Win32.Emotet.684032
RisingTrojan.Kryptik!1.C80B (CLOUD)
Ad-AwareTrojan.Agent.EUFR
SophosTroj/Emotet-CKJ
F-SecureTrojan.TR/AD.Emotet.MH
DrWebTrojan.DownLoader34.9534
TrendMicroTROJ_GEN.R049C0WGT20
EmsisoftTrojan.Emotet (A)
CyrenW32/Emotet.AOD.gen!Eldorado
AviraTR/AD.Emotet.MH
FortinetW32/Emotet.FHGO!tr
ArcabitTrojan.Agent.EUFR
ZoneAlarmBackdoor.Win32.Emotet.ahie
MicrosoftTrojan:Win32/Emotet.PEE!MTB
AhnLab-V3Trojan/Win32.Emotet.R346335
ALYacTrojan.Agent.EUFR
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Emotet.C
ESET-NOD32a variant of Win32/Kryptik.HFFQ
TrendMicro-HouseCallTROJ_GEN.R049C0WGT20
IkarusTrojan-Banker.Emotet
GDataTrojan.Agent.EUFR
BitDefenderThetaGen:NN.ZexaF.34144.Pq0@aWuE1ilj
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.6f1

How to remove Backdoor.Win32.Emotet.ahie?

Backdoor.Win32.Emotet.ahie removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment