Backdoor

Backdoor.Win32.Emotet.bvmm (file analysis)

Malware Removal

The Backdoor.Win32.Emotet.bvmm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bvmm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.bvmm?


File Info:

crc32: 74D1C090
md5: d87477e37312560f6553238b6fb59620
name: upload_file
sha1: 84a9d45005b07aad66ad5f05bc9a41972ba44767
sha256: 3e5642334e2e9cbea90aebf1abefc242dec93dab9442f4690b82cc4ed3261c4f
sha512: 56e4981ab99d1eb02dfec7d6d806718d299ceb2f707061152af592446d117d14d33527491433aff6c6485a7f3bded993296edde4a2abcf722cda3cf562b5db17
ssdeep: 6144:xw6KjnnTFBAiDj+0fTkSGiurL1+sjETSURJ6IV:MtBRDj+0rkThVKNV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003
InternalName: UseShGetFileInfoDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: UseShGetFileInfoDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: UseShGetFileInfoDemo MFC Application
OriginalFilename: UseShGetFileInfoDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bvmm also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69402
FireEyeGeneric.mg.d87477e37312560f
McAfeeEmotet-FQS!D87477E37312
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 0056c5a51 )
BitDefenderTrojan.GenericKDZ.69402
K7GWTrojan ( 0056c5a51 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTROJ_GEN.R002C0DHD20
BitDefenderThetaGen:NN.ZexaF.34152.xq0@a8cbieai
F-ProtW32/Emotet.APH
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HFMJ
TrendMicro-HouseCallTROJ_GEN.R002C0DHD20
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Emotet.bvmm
AlibabaTrojan:Win32/Emotet.b1e28965
RisingTrojan.Kryptik!1.CA6F (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69402
TACHYONTrojan/W32.Agent.380928.AAX
F-SecureTrojan.TR/Crypt.Agent.wkjhn
DrWebTrojan.Emotet.1000
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
SophosTroj/Emotet-CKY
APEXMalicious
CyrenW32/Emotet.QKWG-5644
JiangminBackdoor.Emotet.qo
AviraTR/Crypt.Agent.wkjhn
FortinetW32/Emotet.AJQ!tr
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
ArcabitTrojan.Generic.D10F1A
AhnLab-V3Trojan/Win32.Emotet.R347702
ZoneAlarmBackdoor.Win32.Emotet.bvmm
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 85)
ALYacTrojan.GenericKDZ.69402
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.TRE
IkarusTrojan-Banker.Emotet
PandaTrj/CI.A
TencentMalware.Win32.Gencirc.10cde803
GDataWin32.Trojan.PSE.12DJQCC
AVGWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM41.2.32BB.Malware.Gen

How to remove Backdoor.Win32.Emotet.bvmm?

Backdoor.Win32.Emotet.bvmm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment