Backdoor

Backdoor.Win32.Emotet.avsx information

Malware Removal

The Backdoor.Win32.Emotet.avsx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.avsx virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.avsx?


File Info:

crc32: 81C090FF
md5: 2618c6fb06ce9ee3a24532118ed12202
name: upload_file
sha1: 0a3f40344a5ec67a8d130788660c78eadc30ac19
sha256: 3657c35a561814e723a5db3eab83e312fe7cbc680f8bd66879e0041625108959
sha512: 3296946191c0fcd7b71be3d24f140abcb2a942121cb3ea3f8e6ae1e4238ba10139a4b0c93ebd22fa2e538cfbda18cdc2de79f4875481760a124e12433f848b1b
ssdeep: 12288:Exn1BXbDf5Ss1Opjjy+MdMhzp419mu6JWxE6pKwm7:0bFFOpXy+MR19+W26Uwm7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.avsx also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.43570684
FireEyeGeneric.mg.2618c6fb06ce9ee3
McAfeeGenericRXAA-AA!2618C6FB06CE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.43570684
K7GWTrojan ( 00565ec11 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.43570684
KasperskyBackdoor.Win32.Emotet.avsx
AlibabaTrojan:Win32/GenKryptik.8a87bc83
ViRobotTrojan.Win32.Emotet.917599
RisingTrojan.Kryptik!1.C89F (CLOUD)
Ad-AwareTrojan.GenericKD.43570684
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Emotet.brcbn
DrWebTrojan.Emotet.994
Invinceaheuristic
EmsisoftTrojan.GenericKD.43570684 (B)
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.brcbn
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D298D5FC
ZoneAlarmBackdoor.Win32.Emotet.avsx
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R346576
ALYacTrojan.Agent.Emotet
VBA32BScope.Trojan.Emotet
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HFHK
IkarusTrojan-Downloader.Win32.Icedid
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.ac4

How to remove Backdoor.Win32.Emotet.avsx?

Backdoor.Win32.Emotet.avsx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment