Backdoor

Backdoor.Win32.Emotet.asvt malicious file

Malware Removal

The Backdoor.Win32.Emotet.asvt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.asvt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

How to determine Backdoor.Win32.Emotet.asvt?


File Info:

crc32: 5DA2402A
md5: 041218f43a8fca2a0c940cd37ed1ec16
name: upload_file
sha1: d019fbd72a084e532fe1e4681cef985f0dd91d0f
sha256: 228361b57fb4f3a45e079f219e2653e7809eb81015b75535f98b7cb0e9d422ba
sha512: 6d5b9f0329b2e94add4c16c33a1c2e508973b94ca9137acf9b9fee49a029170e6c262b3cbfea9b243e4543c74d6324c5283aa0bc0b44a3cc25ecbff8396d432c
ssdeep: 12288:/61KBnflNHOvmzIeCHS3/qJd60gmoP1jjv08/adpWxE6pr:/6wXCy3/qJd60gmoP1jjv08/ipW26N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2000
InternalName: MsAgentHelp
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MsAgentHelp Application
ProductVersion: 1, 0, 0, 1
FileDescription: MsAgentHelp MFC Application
OriginalFilename: MsAgentHelp.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.asvt also known as:

FireEyeGeneric.mg.041218f43a8fca2a
McAfeeRDN/Emotet
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056ba541 )
BitDefenderTrojan.GenericKD.34261647
K7GWTrojan ( 0056ba541 )
Invinceaheuristic
F-ProtW32/Kryptik.BSB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.34261647
KasperskyBackdoor.Win32.Emotet.asvt
AlibabaTrojan:Win32/Emotet.e38e1dc2
NANO-AntivirusTrojan.Win32.Emotet.hpmqqv
AegisLabTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.34261647
Ad-AwareTrojan.GenericKD.34261647
EmsisoftTrojan.Emotet (A)
DrWebTrojan.DownLoader34.12533
TrendMicroTROJ_GEN.R002C0DGV20
SophosTroj/Emotet-CKL
IkarusTrojan-Banker.Emotet
CyrenW32/Kryptik.BSB.gen!Eldorado
JiangminBackdoor.Emotet.pf
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D20ACA8F
ZoneAlarmBackdoor.Win32.Emotet.asvt
MicrosoftTrojan:Win32/Emotet.GG!MTB
AhnLab-V3Trojan/Win32.Emotet.R346459
BitDefenderThetaGen:NN.ZexaF.34144.Aq0@aK9OSldi
ALYacTrojan.GenericKD.34261647
TACHYONTrojan/W32.Emotet.438272
VBA32BScope.Trojan.Emotet
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HFGU
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
RisingTrojan.Kryptik!1.C80B (CLOUD)
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.b7e

How to remove Backdoor.Win32.Emotet.asvt?

Backdoor.Win32.Emotet.asvt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment