Backdoor

How to remove “Backdoor.Win32.Emotet.bxer”?

Malware Removal

The Backdoor.Win32.Emotet.bxer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bxer virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.bxer?


File Info:

crc32: 3B372B4D
md5: f622427efdbd371398c67d26fb6a0333
name: upload_file
sha1: aaca223d5b0bc657290fb3c11640c3fc006a953b
sha256: 3bbcaab83e5e6602108e5c5bbe0639de56d60aa02d27f0714cd5b5e66eff92cc
sha512: 03cf1f4004737a5c3b5c3255c3c4454fa045ae696ee0a3663f86bfa4379be38699c2a33876de42e46da8b575ec02d63ff667a3000fa4f5ffc49ef9c8e8ab948f
ssdeep: 1536:ONfzLLSSazj3f0tcC9Rq204xKZHZWX2oppUeCW2Bh:ONLLLSSazj38C2RxePqpUv7H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ListBoxCHDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ListBoxCHDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: ListBoxCHDemo MFC Application
OriginalFilename: ListBoxCHDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bxer also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.Agent.EUWS
FireEyeTrojan.Agent.EUWS
Qihoo-360Generic/Trojan.3fa
McAfeeEmotet-FQS!F622427EFDBD
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.EUWS
K7GWRiskware ( 0040eff71 )
F-ProtW32/Emotet.APO.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
KasperskyBackdoor.Win32.Emotet.bxer
ViRobotTrojan.Win32.Emotet.98304.K
Ad-AwareTrojan.Agent.EUWS
DrWebTrojan.Emotet.999
FortinetW32/Malicious_Behavior.VEX
IkarusTrojan-Banker.Emotet
CyrenW32/Emotet.APO.gen!Eldorado
MAXmalware (ai score=83)
ArcabitTrojan.Agent.EUWS
ZoneAlarmBackdoor.Win32.Emotet.bxer
MicrosoftTrojan:Win32/Emotet.GGG!MTB
AhnLab-V3Trojan/Win32.Emotet.R347787
BitDefenderThetaGen:NN.ZexaF.34152.gq0@a05@m4lj
ALYacTrojan.Agent.EUWS
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HFMM
TrendMicro-HouseCallTROJ_GEN.R002H01HD20
RisingMalware.Heuristic!ET#83% (RDMK:cmRtazrYTE/tSiP/nmXUFJkLtKD6)
eGambitUnsafe.AI_Score_93%
GDataTrojan.Agent.EUWS
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.121218.susgen

How to remove Backdoor.Win32.Emotet.bxer?

Backdoor.Win32.Emotet.bxer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment