Backdoor

Backdoor.Win32.Emotet.aoma information

Malware Removal

The Backdoor.Win32.Emotet.aoma is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.aoma virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.aoma?


File Info:

crc32: 61F13E40
md5: bdd7749286d00fb939a0d6f5320eabc1
name: upload_file
sha1: 2904a206724c2d1010f9a20f77a32b6dd37e1e47
sha256: 01242fb002110dd3ee47d802ed372e4f0271788b8fe289273ef78f56800479f1
sha512: 27201ebc9d80af584615add911c24d36a829b803dd5a13abc1beb4721895da649d3281e4658b4dc5a0c6119aca5126e8f6c9af0c7b71fc3c14101bb86ab3721c
ssdeep: 12288:n/J+NC0xu2rPcHKeNmcZvF/SZGYzZ5Q/dN:/J8R6mcVF/mGY41N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: nlsbres.dll
FileVersion: 6.1.7601.23572 (win7sp1_ldr.161011-0600)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.23572
FileDescription: NLSBuild resource DLL
OriginalFilename: nlsbres.dll
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.aoma also known as:

MicroWorld-eScanTrojan.GenericKD.43569487
FireEyeGeneric.mg.bdd7749286d00fb9
McAfeeEmotet-FRI!BDD7749286D0
MalwarebytesTrojan.Emotet
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056b9711 )
BitDefenderTrojan.GenericKD.43569487
K7GWTrojan ( 0056b9711 )
TrendMicroTROJ_GEN.R011C0DH220
F-ProtW32/Emotet.AOI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.aoma
AlibabaTrojan:Win32/Emotet.2e0cb1cd
ViRobotTrojan.Win32.Emotet.929792
TencentMalware.Win32.Gencirc.10cde54b
Endgamemalicious (high confidence)
SophosTroj/Emotet-CKK
F-SecureTrojan.TR/Kryptik.pszrd
DrWebTrojan.DownLoader34.10773
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.AOI.gen!Eldorado
JiangminBackdoor.Emotet.os
AviraTR/Kryptik.pszrd
FortinetW32/GenKryptik.EPAZ!tr
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Generic.D298D14F
ZoneAlarmBackdoor.Win32.Emotet.aoma
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
TACHYONTrojan/W32.Agent.929792.GE
AhnLab-V3Trojan/Win32.Emotet.R346462
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.43569487
MAXmalware (ai score=100)
Ad-AwareTrojan.GenericKD.43569487
PandaTrj/Emotet.C
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R011C0DH220
RisingTrojan.Kryptik!1.C80B (CLASSIC)
GDataTrojan.GenericKD.43569487
BitDefenderThetaGen:NN.ZexaF.34144.4y0@aWU1YBck
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.49c

How to remove Backdoor.Win32.Emotet.aoma?

Backdoor.Win32.Emotet.aoma removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment