Backdoor

What is “Backdoor.Win32.Emotet.ayxx”?

Malware Removal

The Backdoor.Win32.Emotet.ayxx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.ayxx virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

How to determine Backdoor.Win32.Emotet.ayxx?


File Info:

crc32: 166B0B5F
md5: 66019a6f12679770db92c0a58b90a85a
name: upload_file
sha1: 34764187190b79eec932b9180f14d8c22602a50e
sha256: 34521592f53fe21b6e56bcb74aaaa04a610eead48b4b8ab312385c94cf5e6c57
sha512: 9d6afdbbc62343fa66851d4edcf7db5f3ee097fb7d687bcea7144fd58a32a6dcc02918dca11906a6cf6d1377f784a385db924ca49e0618789341e23deb9d4290
ssdeep: 12288:Kdq2982XqwpszV8ski5NeT0sjVZWtYz2QghDmvQhmHo9LWlNsOY8UuN:KQ291fLski5N6ZWyz2QglbmHo9LGpv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.ayxx also known as:

MicroWorld-eScanTrojan.GenericKD.43576551
FireEyeTrojan.GenericKD.43576551
CAT-QuickHealTrojan.CKGENERIC
McAfeeRDN/Emotet
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.43576551
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.OIFI-8515
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.ayxx
AlibabaTrojan:Win32/Emotet.a1fea5d5
NANO-AntivirusTrojan.Win32.Emotet.hpwjde
AegisLabTrojan.Win32.Emotet.L!c
TencentMalware.Win32.Gencirc.10cde55c
Ad-AwareTrojan.GenericKD.43576551
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/AD.Emotet.dadaq
DrWebTrojan.DownLoader34.14057
ZillyaBackdoor.Emotet.Win32.842
TrendMicroTrojanSpy.Win32.EMOTET.THHODBO
FortinetW32/GenKryptik.EPAZ!tr
SophosTroj/Emotet-CKN
F-ProtW32/Emotet.AOH.gen!Eldorado
JiangminTrojan.Banker.Emotet.oac
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.dadaq
MAXmalware (ai score=83)
Antiy-AVLTrojan[Banker]/Win32.Emotet
ArcabitTrojan.Generic.D298ECE7
ZoneAlarmBackdoor.Win32.Emotet.ayxx
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R346629
ALYacTrojan.Agent.Emotet
TACHYONTrojan/W32.Agent.993792.AK
VBA32BScope.Trojan.Emotet
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HFHN
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THHODBO
RisingTrojan.Kryptik!1.C71F (CLOUD)
IkarusTrojan-Banker.Emotet
GDataTrojan.GenericKD.43576551
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.50c

How to remove Backdoor.Win32.Emotet.ayxx?

Backdoor.Win32.Emotet.ayxx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment