Backdoor

Backdoor.Win32.Emotet.azbb (file analysis)

Malware Removal

The Backdoor.Win32.Emotet.azbb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.azbb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.azbb?


File Info:

crc32: A5448AAE
md5: 640d7fcf270526b4b94371a99ff2a8b1
name: upload_file
sha1: 51237ebf23561b1441d88d4dc3c5c7487ececfb4
sha256: 3d7ec1b9e2b538b154b1ce34da6ce9b7db5eb52038b0f5c66fa5f047083ce98f
sha512: ac9157147594464698b008a7078a8f1c09bd1f66b0127bec4f35bca5f495494c20e1bf79a2cb2f9bce94244cb8ce2c78ac9ccf2f4c3823ce074e595340dcfeef
ssdeep: 12288:xdq2982XqwpszV8ski5NeT0sjVZWtYz2QghDmvQhmHo9LWlXW4Y8c5B:xQ291fLski5N6ZWyz2QglbmHo9LG7c5B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.azbb also known as:

MicroWorld-eScanTrojan.GenericKD.34280778
FireEyeTrojan.GenericKD.34280778
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FRI!640D7FCF2705
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34280778
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
F-ProtW32/Emotet.AOH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.azbb
AlibabaTrojan:Win32/Emotet.b249dafa
NANO-AntivirusTrojan.Win32.Emotet.hpwjde
AegisLabTrojan.Win32.Emotet.L!c
RisingTrojan.Kryptik!1.C71F (CLASSIC)
Ad-AwareTrojan.GenericKD.34280778
EmsisoftTrojan.Emotet (A)
DrWebTrojan.DownLoader34.14057
ZillyaBackdoor.Emotet.Win32.842
TrendMicroTROJ_GEN.R002C0DH120
FortinetW32/GenKryptik.EPAZ!tr
SophosTroj/Emotet-CKN
IkarusTrojan-Banker.Emotet
CyrenW32/Trojan.JTSY-3690
JiangminTrojan.Banker.Emotet.oac
MaxSecureTrojan.Malware.121218.susgen
AviraTR/AD.Emotet.mickj
Antiy-AVLTrojan[Banker]/Win32.Emotet
ArcabitTrojan.Generic.D20B154A
ZoneAlarmBackdoor.Win32.Emotet.azbb
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R346629
ALYacTrojan.GenericKD.34280778
VBA32BScope.Trojan.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HFHN
TrendMicro-HouseCallTROJ_GEN.R002C0DH120
TencentMalware.Win32.Gencirc.10cde55c
GDataTrojan.GenericKD.34280778
WebrootW32.Trojan.Emotet
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Generic/Trojan.50c

How to remove Backdoor.Win32.Emotet.azbb?

Backdoor.Win32.Emotet.azbb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment