Backdoor

Should I remove “Backdoor.Win32.Emotet.bsqi”?

Malware Removal

The Backdoor.Win32.Emotet.bsqi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bsqi virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.bsqi?


File Info:

crc32: FD1D1382
md5: c0ac3402c21304ad492e0bd0b84761ea
name: upload_file
sha1: 35bab474a7733b18570fb179b0dccd7f4ab9d553
sha256: d20bf13318c12eb57c46ea873827ee1419609845e47fab6418b2793b6167f0c2
sha512: efbd3a64698af256057b07d3f6b9de9280ed63e2741174d9935419d815f88d47f63be3247e466bb3406988d6be035e39dbda3092a86dfaf5f3c307543ed807fc
ssdeep: 768:LDEgbXnp5TK0LR8n4oWPjia5xkkro02iIUUcwORYF97mXYYDENjNUCo:S0LOjAv0sUOY9qowiUC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003
InternalName: UseShGetFileInfoDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: UseShGetFileInfoDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: UseShGetFileInfoDemo MFC Application
OriginalFilename: UseShGetFileInfoDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bsqi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ranapama.ALM
ALYacTrojan.Ranapama.ALM
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Ranapama.ALM
K7GWRiskware ( 0040eff71 )
F-ProtW32/Kryptik.BTL.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
KasperskyBackdoor.Win32.Emotet.bsqi
AlibabaTrojan:Win32/Emotet.a189c87d
ViRobotTrojan.Win32.Emotet.61440
Ad-AwareTrojan.Ranapama.ALM
TACHYONTrojan/W32.Ranapama.61440
Comodo.UnclassifiedMalware@0
DrWebTrojan.Emotet.1000
Invinceaheuristic
FireEyeTrojan.Ranapama.ALM
SophosMal/Generic-S
CyrenW32/Kryptik.BTL.gen!Eldorado
FortinetW32/Malicious_Behavior.VEX
ArcabitTrojan.Ranapama.ALM
ZoneAlarmBackdoor.Win32.Emotet.bsqi
MicrosoftTrojan:Win32/Emotet.GGG!MTB
MAXmalware (ai score=82)
VBA32BScope.TrojanBanker.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Emotet.C
ESET-NOD32a variant of Win32/Kryptik.HFMI
TrendMicro-HouseCallTROJ_GEN.R002C0DHD20
RisingMalware.Heuristic!ET#83% (RDMK:cmRtazp9ujv5IaTSMhfZeajxicVb)
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_99%
GDataTrojan.Ranapama.ALM
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.326

How to remove Backdoor.Win32.Emotet.bsqi?

Backdoor.Win32.Emotet.bsqi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment