Backdoor

Should I remove “Backdoor.Win32.Emotet.bagp”?

Malware Removal

The Backdoor.Win32.Emotet.bagp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bagp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.bagp?


File Info:

crc32: 370AFA1A
md5: 5fd4d624527b7785754aceca446cad85
name: upload_file
sha1: d205d81dfb9f1a2448785f0688eb9d8db0411db1
sha256: 43740d948cc14b8bcf35ef4d7b00ba351614c9fd8680097c156baa979ffc18a4
sha512: 5b5f1fffc631358c7c4a8a1734ef78d18e16f9ea8d15e43649a2518730b122c844ea6a358e904d91cbe79bc37a2c71158c71d00b411124de33799c53f5e67b1e
ssdeep: 6144:lqpqdUS0u6jJ6KfkWdjCuv4ZVmeg755iLNVfhR792H:lqp8US0HFXfRBDmLNVfhm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: DriveBrowsingTree
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: DriveBrowsingTree Application
ProductVersion: 1, 0, 0, 1
FileDescription: DriveBrowsingTree MFC Application
OriginalFilename: DriveBrowsingTree.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bagp also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.DownLoader34.14115
MicroWorld-eScanTrojan.GenericKD.34280767
FireEyeTrojan.GenericKD.34280767
CAT-QuickHealBackdoor.Emotet
ALYacTrojan.GenericKD.34280767
CylanceUnsafe
ZillyaBackdoor.Emotet.Win32.840
K7AntiVirusTrojan ( 0056bb381 )
BitDefenderTrojan.GenericKD.34280767
K7GWTrojan ( 0056bb381 )
TrendMicroTrojan.Win32.WACATAC.THHOABO
F-ProtW32/Emotet.AOG.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.34280767
KasperskyBackdoor.Win32.Emotet.bagp
AlibabaTrojan:Win32/Emotet.67945609
NANO-AntivirusTrojan.Win32.Emotet.hptagd
AegisLabTrojan.Win32.Emotet.L!c
TencentMalware.Win32.Gencirc.10cde545
Ad-AwareTrojan.GenericKD.34280767
SophosTroj/Emotet-CKO
F-SecureTrojan.TR/Kryptik.otkjk
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.AOG.gen!Eldorado
JiangminBackdoor.Emotet.pl
AviraTR/Kryptik.otkjk
MAXmalware (ai score=84)
Antiy-AVLTrojan[Banker]/Win32.Emotet
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D20B153F
ZoneAlarmBackdoor.Win32.Emotet.bagp
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4173829
McAfeeEmotet-FRO!5FD4D624527B
TACHYONTrojan/W32.Agent.380928.AAW
VBA32BScope.Trojan.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/GenKryptik.EPMC
TrendMicro-HouseCallTrojan.Win32.WACATAC.THHOABO
RisingTrojan.Kryptik!1.C89F (CLOUD)
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Generic/Trojan.f4b

How to remove Backdoor.Win32.Emotet.bagp?

Backdoor.Win32.Emotet.bagp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment