Backdoor

Backdoor.Win32.Emotet.baex malicious file

Malware Removal

The Backdoor.Win32.Emotet.baex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.baex virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.baex?


File Info:

crc32: 222ECEDC
md5: 132eeb5dd017b44cbd07d1fbf053b7d3
name: upload_file
sha1: 139efc053dbdd5da3011654bbc5d69f85e7ad234
sha256: 9366f0d692cecb3b0bc4c38c0d8518e598f33925ffa23caba47808b8a6724607
sha512: 39f52e932041279b7ff39b2e9677f2b9bceb9fc804bdd7e500bc1a281ef2f8da84f0432ca31d81b87811e7b9cf2a70e29f9d7501cfcf698f0c78ff7cfa00ca95
ssdeep: 6144:fsAXvtkXZjPfQ72jfw9LZ3fUIKonW1WAEgjrqV8FH:fZftkJjXCU8Z3cfoIEqh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: DriveBrowsingTree
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: DriveBrowsingTree Application
ProductVersion: 1, 0, 0, 1
FileDescription: DriveBrowsingTree MFC Application
OriginalFilename: DriveBrowsingTree.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.baex also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.43615084
FireEyeGeneric.mg.132eeb5dd017b44c
CAT-QuickHealBackdoor.Emotet
ALYacTrojan.GenericKD.43615084
MalwarebytesTrojan.Emotet
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.43615084
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
CyrenW32/Emotet.AOG.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DH220
Paloaltogeneric.ml
GDataTrojan.GenericKD.43615084
KasperskyBackdoor.Win32.Emotet.baex
AlibabaTrojan:Win32/Emotet.574c5971
NANO-AntivirusTrojan.Win32.Kryptik.hpnoph
ViRobotTrojan.Win32.Emotet.401408.D
TencentMalware.Win32.Gencirc.10cde567
Ad-AwareTrojan.GenericKD.43615084
TACHYONBanker/W32.Emotet.401408.R
EmsisoftTrojan.Emotet (A)
DrWebTrojan.DownLoader34.14215
ZillyaBackdoor.Emotet.Win32.847
TrendMicroTROJ_GEN.R002C0DH220
SophosTroj/Emotet-CKO
APEXMalicious
F-ProtW32/Emotet.AOG.gen!Eldorado
JiangminBackdoor.Emotet.pm
WebrootW32.Trojan.Emotet
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ZoneAlarmBackdoor.Win32.Emotet.baex
MicrosoftTrojan:Win32/Emotet.DGM!MTB
AhnLab-V3Trojan/Win32.Emotet.R346631
McAfeeEmotet-FRO!132EEB5DD017
MAXmalware (ai score=84)
VBA32BScope.Trojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HFHN
RisingTrojan.Kryptik!1.C82B (CLASSIC)
IkarusTrojan-Banker.Emotet
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
Qihoo-360Win32/Backdoor.f0e

How to remove Backdoor.Win32.Emotet.baex?

Backdoor.Win32.Emotet.baex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment