Backdoor

How to remove “Backdoor.Win32.Emotet.aszl”?

Malware Removal

The Backdoor.Win32.Emotet.aszl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.aszl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

How to determine Backdoor.Win32.Emotet.aszl?


File Info:

crc32: E9DA486D
md5: ff7e1f197ddabf9ebe9491a68fc8fe85
name: upload_file
sha1: f8dff7c588a78dd581e949dc47573624e22e8804
sha256: aefbe837a6f22be28dea2f22f1d7d3d993854c52214216b53d1041abf69b42bd
sha512: 684c717acbaf4be4f1efaf92f4695777e32782dfde923df35b82bfb14167f4cf1168ecc4320d5905b0f24f49e020d62b45f08fb6e5695e3c550aa36b6f8c8e64
ssdeep: 12288:d61KBnflNHOvmzIeCHO3/qJd60gmoP1jjv08/adpTK:d6wXCu3/qJd60gmoP1jjv08/ipTK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2000
InternalName: MsAgentHelp
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MsAgentHelp Application
ProductVersion: 1, 0, 0, 1
FileDescription: MsAgentHelp MFC Application
OriginalFilename: MsAgentHelp.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.aszl also known as:

MicroWorld-eScanTrojan.GenericKDZ.69134
FireEyeGeneric.mg.ff7e1f197ddabf9e
Qihoo-360Win32/Backdoor.570
ALYacTrojan.GenericKDZ.69134
MalwarebytesTrojan.MalPack.TRE
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056ba3c1 )
BitDefenderTrojan.GenericKDZ.69134
K7GWTrojan ( 0056ba3c1 )
TrendMicroTrojanSpy.Win32.EMOTET.THGCABO
BitDefenderThetaGen:NN.ZexaF.34144.Aq0@aKoShKai
F-ProtW32/Emotet.AOL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HFGU
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKDZ.69134
KasperskyBackdoor.Win32.Emotet.aszl
AlibabaTrojan:Win32/Emotet.6d4eedeb
NANO-AntivirusTrojan.Win32.Emotet.hpmqqv
AegisLabTrojan.Win32.Emotet.L!c
TencentWin32.Backdoor.Emotet.Egok
Ad-AwareTrojan.GenericKDZ.69134
TACHYONTrojan/W32.Emotet.438272
SophosTroj/Emotet-CKL
F-SecureTrojan.TR/AD.Emotet.TP
DrWebTrojan.DownLoader34.12533
Invinceaheuristic
EmsisoftTrojan.Emotet (A)
CyrenW32/Emotet.AOL.gen!Eldorado
JiangminBackdoor.Emotet.pf
AviraTR/AD.Emotet.TP
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D10E0E
AhnLab-V3Trojan/Win32.Emotet.R346459
ZoneAlarmBackdoor.Win32.Emotet.aszl
MicrosoftTrojan:Win32/Emotet.GG!MTB
CynetMalicious (score: 85)
McAfeeEmotet-FRI!FF7E1F197DDA
MAXmalware (ai score=81)
VBA32BScope.Trojan.Emotet
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THGCABO
RisingTrojan.Kryptik!1.C80B (CLOUD)
IkarusTrojan-Banker.Emotet
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Backdoor.Win32.Emotet.aszl?

Backdoor.Win32.Emotet.aszl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment