Backdoor

Backdoor.Win32.Emotet.awou removal tips

Malware Removal

The Backdoor.Win32.Emotet.awou is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.awou virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.awou?


File Info:

crc32: 1B07575C
md5: e0ea8ed4b5746a5d7f3336fc1bf3c8ec
name: upload_file
sha1: e0ec4735959425ed7afade69d4f7103d48a4e310
sha256: e98de7ad111e8126ca64321a18029426caf885ab3511e17cbd1de1c329c455ca
sha512: 5851923767f3001e2662300456638afacdfb2a5b3c113969116ea0dbd324ad259df427da19a4ddb70b51628a8d899bc1ed5baca5ffb4bb80c336d81c7d0d8aae
ssdeep: 3072:DQAtEQkstBPSl0YW/i/WUWHLiMrHL9b5nEviJHccd:DLEOVSGYW6CHOMrHJxE6JHc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.awou also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Agent.EUIE
FireEyeTrojan.Agent.EUIE
CAT-QuickHealTrojan.Wacatac
ALYacTrojan.Agent.EUIE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056aa7c1 )
BitDefenderTrojan.Agent.EUIE
K7GWTrojan ( 0056aa7c1 )
TrendMicroTROJ_GEN.R002C0DGV20
CyrenW32/Emotet.AOH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.Agent.EUIE
KasperskyBackdoor.Win32.Emotet.awou
AlibabaTrojan:Win32/Emotet.0044bcd1
NANO-AntivirusTrojan.Win32.Emotet.hpnmal
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10cde55b
Ad-AwareTrojan.Agent.EUIE
SophosTroj/Emotet-CKN
F-SecureTrojan.TR/Crypt.Agent.xilij
DrWebTrojan.DownLoader34.14035
ZillyaBackdoor.Emotet.Win32.841
EmsisoftTrojan.Emotet (A)
F-ProtW32/Emotet.AOH.gen!Eldorado
JiangminBackdoor.Emotet.ph
AviraTR/Crypt.Agent.xilij
ArcabitTrojan.Agent.EUIE
ZoneAlarmBackdoor.Win32.Emotet.awou
MicrosoftTrojan:Win32/Emotet.AER!MTB
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4172970
McAfeeEmotet-FRI!E0EA8ED4B574
VBA32Trojan.Emotet
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HEWN
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
RisingTrojan.Kryptik!1.C89F (CLOUD)
MAXmalware (ai score=83)
FortinetW32/GenKryptik.EOMR!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Backdoor.665

How to remove Backdoor.Win32.Emotet.awou?

Backdoor.Win32.Emotet.awou removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment