Backdoor

Backdoor.Win32.Emotet.avgm removal instruction

Malware Removal

The Backdoor.Win32.Emotet.avgm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.avgm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

How to determine Backdoor.Win32.Emotet.avgm?


File Info:

crc32: 818ED09E
md5: 01da6389109a5edb703b9aef6fcf24fb
name: upload_file
sha1: d1b4307ce16724751e6c6a2ce6f9bf65dabfa16a
sha256: 73702a31444153420ddaf126bfe0b545c09f4d8639e44b0cbd6b718752cedfd9
sha512: 33cb35f10fd4898ccc40883cae8dc1d5a7c59af72fd59941b10ed1acb9ef51d8a061d832761bfce47442c673d5dfe7b1ef5aa68e9ecf7e158a0c363bde23f55c
ssdeep: 3072:7QAtEQkstBPSl+W/i/WUWHLiMrHL9b5nEviJHccd:7LEOVSkW6CHOMrHJxE6JHc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.avgm also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.DownLoader34.14035
MicroWorld-eScanTrojan.GenericKD.34263869
FireEyeTrojan.GenericKD.34263869
McAfeeEmotet-FRI!01DA6389109A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056aa7c1 )
AlibabaTrojan:Win32/Emotet.3efb7df6
K7GWTrojan ( 0056aa7c1 )
ArcabitTrojan.Generic.D20AD33D
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HEWN
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Emotet.avgm
BitDefenderTrojan.GenericKD.34263869
NANO-AntivirusTrojan.Win32.Emotet.hpnmal
Paloaltogeneric.ml
RisingTrojan.Kryptik!1.C89F (CLOUD)
EmsisoftTrojan.Emotet (A)
ZillyaBackdoor.Emotet.Win32.841
TrendMicroTROJ_GEN.R002C0DGV20
SophosTroj/Emotet-CKN
CyrenW32/Emotet.AOH.gen!Eldorado
JiangminBackdoor.Emotet.ph
FortinetW32/GenKryptik.EOMR!tr
Antiy-AVLTrojan/Win32.Injuke
MicrosoftTrojan:Win32/Emotet.AER!MTB
ZoneAlarmBackdoor.Win32.Emotet.avgm
AhnLab-V3Malware/Win32.Generic.C4172970
VBA32Trojan.Emotet
ALYacTrojan.GenericKD.34263869
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.34263869
MalwarebytesTrojan.MalPack.TRE
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
TencentMalware.Win32.Gencirc.10cde55b
IkarusTrojan-Banker.Emotet
GDataTrojan.GenericKD.34263869
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.f9f

How to remove Backdoor.Win32.Emotet.avgm?

Backdoor.Win32.Emotet.avgm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment