Backdoor

About “Backdoor.Win32.Emotet.bblu” infection

Malware Removal

The Backdoor.Win32.Emotet.bblu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bblu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.bblu?


File Info:

crc32: 0FE86A07
md5: 4e941432df3d782456aa6470c379bc0e
name: upload_file
sha1: e0e5a4ad62a762dccd7f8667f37c17a20b369dfe
sha256: f9d296084482d684eccd922ab0f45abb3a83234d79e5455eecf0ca3e6ebc6f27
sha512: f20816aa331bafabdba19d70d84d82dec4f5709ce9e63faa55df8d220deb0135fae62c9b4c6e01fb10879a60b2c6a772b982f9b9fccd43d7c020a6f85d2a79da
ssdeep: 12288:Fdq2982XqwpszV8ski5NeT0sjVZWtYz2QghDmvQhmHo9LWlXW4Y8c5Z:FQ291fLski5N6ZWyz2QglbmHo9LG7c5Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: TabDrives
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TabDrives Application
ProductVersion: 1, 0, 0, 1
FileDescription: TabDrives MFC Application
OriginalFilename: TabDrives.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bblu also known as:

DrWebTrojan.DownLoader34.14057
MicroWorld-eScanTrojan.GenericKDZ.69165
FireEyeTrojan.GenericKDZ.69165
CAT-QuickHealBackdoor.Emotet
McAfeeEmotet-FRI!4E941432DF3D
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69165
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0DH120
CyrenW32/Emotet.AOH.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DH120
AvastWin32:Malware-gen
GDataTrojan.GenericKDZ.69165
KasperskyBackdoor.Win32.Emotet.bblu
AlibabaTrojan:Win32/Emotet.5d81db3e
NANO-AntivirusTrojan.Win32.Emotet.hpwjde
AegisLabTrojan.Win32.Emotet.L!c
TencentMalware.Win32.Gencirc.10cde55c
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/AD.Emotet.mickj
ZillyaBackdoor.Emotet.Win32.842
SophosTroj/Emotet-CKN
IkarusTrojan-Banker.Emotet
F-ProtW32/Emotet.AOH.gen!Eldorado
JiangminTrojan.Banker.Emotet.oac
AviraTR/AD.Emotet.mickj
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D10E2D
ZoneAlarmBackdoor.Win32.Emotet.bblu
AhnLab-V3Trojan/Win32.Emotet.R346629
VBA32BScope.Trojan.Emotet
ALYacTrojan.GenericKDZ.69165
MAXmalware (ai score=84)
Ad-AwareTrojan.GenericKDZ.69165
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HFHN
RisingTrojan.Kryptik!1.C71F (CLOUD)
FortinetW32/GenKryptik.EPAZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.c9e

How to remove Backdoor.Win32.Emotet.bblu?

Backdoor.Win32.Emotet.bblu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment