Backdoor

Backdoor.Win32.Emotet.aymp removal guide

Malware Removal

The Backdoor.Win32.Emotet.aymp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.aymp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

How to determine Backdoor.Win32.Emotet.aymp?


File Info:

crc32: EEB7DDE7
md5: 095fd871c6e4d50c5baafed9cf5a1d07
name: upload_file
sha1: 8c5b1b5290268adde486b9968fba6ab80b29d112
sha256: 7f84204a815be4ba2a95fff0e891e41767c2e20140f22e1495624a8128da1ec0
sha512: 02a97d9e742789d2863045df89a3e4e71d73ac40194e552a9fb6763194b35735d33db3829654ca0c434bc9892e66146d30a7385dd31500840c9bb6b81cadcb92
ssdeep: 12288:761KBnflNHOvmzIeCHw3/qJd60gmoP1jjv08/adpWxE6pr:76wXCQ3/qJd60gmoP1jjv08/ipW26N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2000
InternalName: MsAgentHelp
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MsAgentHelp Application
ProductVersion: 1, 0, 0, 1
FileDescription: MsAgentHelp MFC Application
OriginalFilename: MsAgentHelp.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.aymp also known as:

DrWebTrojan.DownLoader34.12533
MicroWorld-eScanTrojan.GenericKD.34266213
FireEyeGeneric.mg.095fd871c6e4d50c
Qihoo-360Win32/Backdoor.728
McAfeeEmotet-FRI!095FD871C6E4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34266213
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34144.Aq0@ayuNjPai
F-ProtW32/Kryptik.BSB.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
AvastWin32:Malware-gen
GDataTrojan.GenericKD.34266213
KasperskyBackdoor.Win32.Emotet.aymp
AlibabaTrojan:Win32/Emotet.d6d8ab4a
NANO-AntivirusTrojan.Win32.Emotet.hpmqqv
AegisLabTrojan.Win32.Emotet.L!c
Endgamemalicious (high confidence)
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/Crypt.Agent.zswzr
TrendMicroTROJ_GEN.R002C0DGV20
SophosTroj/Emotet-CKL
IkarusTrojan-Banker.Emotet
CyrenW32/Kryptik.BSB.gen!Eldorado
JiangminBackdoor.Emotet.pf
AviraTR/Crypt.Agent.zswzr
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D20ADC65
ZoneAlarmBackdoor.Win32.Emotet.aymp
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R346459
VBA32BScope.Trojan.Emotet
ALYacTrojan.GenericKD.34266213
TACHYONTrojan/W32.Emotet.438272
Ad-AwareTrojan.GenericKD.34266213
MalwarebytesTrojan.MalPack.TRE
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HFGU
RisingTrojan.Kryptik!1.C80B (CLOUD)
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Win32.Emotet.aymp?

Backdoor.Win32.Emotet.aymp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment