Backdoor

Backdoor.Win32.Emotet.bzlk malicious file

Malware Removal

The Backdoor.Win32.Emotet.bzlk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.bzlk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Emotet.bzlk?


File Info:

crc32: 31FD2D8F
md5: 62ea9e87d3fde2a14b918165e5c1772c
name: upload_file
sha1: 552dd8dcbe231f7b049b3ce46e4b3eb11382bfe5
sha256: 62bd81c7444a2a2315340144105665e2e22112c3ef6f5a95bd20512bbcf0823d
sha512: a20f1471b46a120be679820951e80b820aaa2b5acea1b8a2758b9da0d7a56acd2ae25e646e673768154ab8feb870e4c28cb9c18abb842fe182dc7b16806ff4a0
ssdeep: 3072:2pocVfb++Xuy7YXDxaOhlSsBpkxno3mOuTXd4LltbTSdKekyOI:kDZ++eNTxyQkucXd4LltbT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.bzlk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Emotet.1000
MicroWorld-eScanTrojan.GenericKD.34359294
FireEyeGeneric.mg.62ea9e87d3fde2a1
CAT-QuickHealTrojan.CKGENERIC
Qihoo-360Win32/Backdoor.679
McAfeeEmotet-FQS!62EA9E87D3FD
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056c87c1 )
BitDefenderTrojan.GenericKD.34359294
K7GWTrojan ( 0056c87c1 )
TrendMicroTrojanSpy.Win32.EMOTET.THHAEBO
CyrenW32/Emotet.APS.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THHAEBO
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Emotet-9371538-0
KasperskyBackdoor.Win32.Emotet.bzlk
AlibabaTrojan:Win32/Emotet.474c40f6
ViRobotTrojan.Win32.Emotet.188416.B
TencentMalware.Win32.Gencirc.10cde85d
Ad-AwareTrojan.GenericKD.34359294
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Crypt.Agent.nxrmq
ZillyaBackdoor.Emotet.Win32.1035
SophosTroj/Emotet-CLB
IkarusTrojan-Banker.Emotet
JiangminBackdoor.Emotet.qv
AviraTR/Crypt.Agent.nxrmq
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.AER!MTB
ArcabitTrojan.Generic.D20C47FE
ZoneAlarmBackdoor.Win32.Emotet.bzlk
GDataTrojan.GenericKD.34359294
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R348051
VBA32Backdoor.Emotet
ALYacTrojan.Agent.Emotet
TACHYONBackdoor/W32.Emotet.188416
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HFMZ
RisingTrojan.Emotet!8.B95 (CLOUD)
FortinetW32/Kryptik.HCEJ!tr
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.105306427.susgen

How to remove Backdoor.Win32.Emotet.bzlk?

Backdoor.Win32.Emotet.bzlk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment