Backdoor

Backdoor.Win32.Emotet.bain malicious file

Malware Removal

The Backdoor.Win32.Emotet.bain is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bain virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.bain?


File Info:

crc32: EC0D665A
md5: ab32c87934544159b6526af74ede5856
name: upload_file
sha1: d7124c3678ea3a5781de6426404a28778214d51f
sha256: bbd0161f437da1bb17688d06fbb82df750dbdc7088cbb8225312eddf12609828
sha512: 9a922ddd7fa8fce9623d11159f19db7de8ed5c0a043f64fda0ab1cdab424137b5f9c18a7bb4e593b4daada957a6c4b3af71ccd284fed405d4f971e7e997182bc
ssdeep: 6144:gsAXvtkXZjPfQ72jfw9LZ3fUIKonW1WAEgjrqVdFH:gZftkJjXCU8Z3cfoIEqW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: DriveBrowsingTree
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: DriveBrowsingTree Application
ProductVersion: 1, 0, 0, 1
FileDescription: DriveBrowsingTree MFC Application
OriginalFilename: DriveBrowsingTree.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bain also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKDZ.69173
FireEyeGeneric.mg.ab32c87934544159
McAfeeEmotet-FRO!AB32C8793454
CylanceUnsafe
BitDefenderTrojan.GenericKDZ.69173
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKDZ.69173
KasperskyBackdoor.Win32.Emotet.bain
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Backdoor.Emotet.Lmuc
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKDZ.69173 (B)
F-SecureTrojan.TR/Crypt.Agent.uxmdd
DrWebTrojan.DownLoader34.14215
TrendMicroTROJ_GEN.R06BC0DH220
SophosTroj/Emotet-CKO
CyrenW32/Trojan.GMGU-2648
WebrootW32.Trojan.Emotet
AviraTR/Crypt.Agent.uxmdd
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D10E35
ZoneAlarmBackdoor.Win32.Emotet.bain
MicrosoftTrojan:Win32/Emotet.DGM!MTB
CynetMalicious (score: 85)
VBA32BScope.Trojan.Emotet
ALYacTrojan.GenericKDZ.69173
Ad-AwareTrojan.GenericKDZ.69173
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HFHN
TrendMicro-HouseCallTROJ_GEN.R06BC0DH220
RisingTrojan.Kryptik!1.C82B (CLOUD)
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.dcf

How to remove Backdoor.Win32.Emotet.bain?

Backdoor.Win32.Emotet.bain removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment