Backdoor

Backdoor.Win32.Emotet.amtv removal instruction

Malware Removal

The Backdoor.Win32.Emotet.amtv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.amtv virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Emotet.amtv?


File Info:

crc32: FA3EBD62
md5: f5162da9c6c6e0838e2fcbce23e4f74d
name: upload_file
sha1: 6d4b89777a0241f734937b8ef08dd9ac923a1910
sha256: 69fb8b744a5ac95adb7a827674c8cf7e1e52e00a435e1df6d2c7e6c447024f74
sha512: cb6a8953fa52aa61deb453232845548f8bd2ec6b5d8226a4485d13e9a9c2f33fb5e79553eb86a6c707cac3d4d3bac3d97b795dd6bf98e77f2374f0a3bea82ff9
ssdeep: 6144:xPHIFvHxVBxWrhtOjMcD+t14e13gvXr7fa+CYSerSiNX:xPoFPxVB0r/OjMciV1yja+3n3N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: nlsbres.dll
FileVersion: 6.1.7601.23572 (win7sp1_ldr.161011-0600)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.23572
FileDescription: NLSBuild resource DLL
OriginalFilename: nlsbres.dll
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.amtv also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.10090
MicroWorld-eScanTrojan.GenericKDZ.69120
FireEyeTrojan.GenericKDZ.69120
ALYacTrojan.Agent.EUGP
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKDZ.69120
K7GWTrojan ( 0056b94b1 )
K7AntiVirusTrojan ( 0056b94b1 )
BitDefenderThetaGen:NN.Zextet.34144.vq0@aa3IHidk
CyrenW32/Kryptik.BRY.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyBackdoor.Win32.Emotet.amtv
AlibabaTrojan:Win32/GenKryptik.8de8d1c1
RisingTrojan.Kryptik!1.C82B (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69120
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.wssca
Invinceaheuristic
EmsisoftTrojan.Emotet (A)
IkarusTrojan.Win32.Krypt
F-ProtW32/Kryptik.BRY.gen!Eldorado
AviraTR/Kryptik.wssca
FortinetW32/GenKryptik.EPAZ!tr
ArcabitTrojan.Generic.D10E00
ZoneAlarmBackdoor.Win32.Emotet.amtv
MicrosoftTrojan:Win32/Emotet.DGK!MTB
AhnLab-V3Trojan/Win32.Kryptik.R346329
McAfeeEmotet-FRI!F5162DA9C6C6
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/GenKryptik.EPHQ
GDataTrojan.GenericKDZ.69120
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.af9

How to remove Backdoor.Win32.Emotet.amtv?

Backdoor.Win32.Emotet.amtv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment