Backdoor

Backdoor.Win32.Emotet.aifz malicious file

Malware Removal

The Backdoor.Win32.Emotet.aifz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.aifz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.aifz?


File Info:

crc32: 40AFD02B
md5: edab9c08c10adde7f324b5b5192e4dce
name: upload_file
sha1: fe9c59ef8a371a42b77af03f91e475403544485e
sha256: 51bfc7bf0e50bab7f849a9b398661f96e456a532e1e3bbda76d52656bfb66ac4
sha512: 0341fcff7f6a8cf195a90be7b59077e02d228f41285577bdab3e5bbaac06bc8e247606723a8c7ecd8d82ad1ba93d4e30fcf84b3696319749e5b210fc34f5d6cb
ssdeep: 12288:p2NVqHzevfqCG8pInsjtoXejRnBMm8y3Q:p2KWfqmpI+oyp0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: CHexEditDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CHexEditDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: CHexEditDemo MFC Application
OriginalFilename: CHexEditDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.aifz also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EUFR
FireEyeGeneric.mg.edab9c08c10adde7
McAfeeEmotet-FRI!EDAB9C08C10A
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056b6ba1 )
BitDefenderTrojan.Agent.EUFR
K7GWTrojan ( 0056b6ba1 )
TrendMicroTROJ_GEN.R002C0DGU20
CyrenW32/Emotet.AOD.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.aifz
AlibabaTrojan:Win32/Emotet.4e55a2d1
ViRobotTrojan.Win32.Emotet.684032
AegisLabTrojan.Win32.Generic.4!c
AvastWin32:BankerX-gen [Trj]
Ad-AwareTrojan.Agent.EUFR
SophosTroj/Emotet-CKJ
F-SecureTrojan.TR/Kryptik.kdxea
DrWebTrojan.DownLoader34.9534
Invinceaheuristic
FortinetW32/Emotet.FHGO!tr
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
F-ProtW32/Emotet.AOD.gen!Eldorado
JiangminBackdoor.Emotet.oq
AviraTR/Kryptik.kdxea
MAXmalware (ai score=81)
ArcabitTrojan.Agent.EUFR
ZoneAlarmBackdoor.Win32.Emotet.aifz
MicrosoftTrojan:Win32/Emotet.PEE!MTB
AhnLab-V3Trojan/Win32.Emotet.R346335
BitDefenderThetaGen:NN.ZexaF.34144.Pq0@aiwHZVej
ALYacTrojan.Agent.EUFR
TACHYONBackdoor/W32.Emotet.684032
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HFFQ
TrendMicro-HouseCallTROJ_GEN.R002C0DGU20
RisingTrojan.Kryptik!1.C80B (CLOUD)
GDataTrojan.Agent.EUFR
AVGWin32:BankerX-gen [Trj]
PandaTrj/Emotet.C
Qihoo-360Win32/Trojan.653

How to remove Backdoor.Win32.Emotet.aifz?

Backdoor.Win32.Emotet.aifz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment