Backdoor

About “Backdoor.Win32.Emotet.awaf” infection

Malware Removal

The Backdoor.Win32.Emotet.awaf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.awaf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.awaf?


File Info:

crc32: EBEA0DC7
md5: 5836369ff8a9d7cafc3f60a5786dbcec
name: upload_file
sha1: 926db710e3cd8af607834236fed1b3d3d9a6b5cb
sha256: 36db9575c51cbb1542300cf330b32a5dfd4999d6b62ed7d3453a02daaa7876db
sha512: 970b0eb66c0b374d282836273d4ca5e611c3cc0a56f42a2be740e00dcefbe1b1aa06dcbe44d94c7e14124f5bdc85235b2ba965c51bcfc06611288685279266a6
ssdeep: 12288:Fxn1BXbDf5Ss1Opjjy+MdMhzp419mu6JWxE6pfwm7:LbFFOpXy+MR19+W26Jwm7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.awaf also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKDZ.69152
FireEyeGeneric.mg.5836369ff8a9d7ca
McAfeeGenericRXAA-AA!5836369FF8A9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKDZ.69152
K7GWTrojan ( 00565ec11 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKDZ.69152
KasperskyBackdoor.Win32.Emotet.awaf
AlibabaTrojan:Win32/GenKryptik.07d9de0c
ViRobotTrojan.Win32.Emotet.917599
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Emotet.travk
DrWebTrojan.Emotet.994
Invinceaheuristic
EmsisoftTrojan.GenericKDZ.69152 (B)
IkarusTrojan-Downloader.Win32.Icedid
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.travk
ArcabitTrojan.Generic.D10E20
ZoneAlarmBackdoor.Win32.Emotet.awaf
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R346576
VBA32BScope.Trojan.Emotet
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKDZ.69152
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HFHK
RisingTrojan.Kryptik!1.C89F (CLOUD)
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.86d

How to remove Backdoor.Win32.Emotet.awaf?

Backdoor.Win32.Emotet.awaf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment