Backdoor

About “Backdoor.Win32.Emotet.cabw” infection

Malware Removal

The Backdoor.Win32.Emotet.cabw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cabw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Emotet.cabw?


File Info:

crc32: EE7308C6
md5: 033d36eb6eaf7b9602a1c88ff9c62274
name: upload_file
sha1: 4de3c790d267ca0547d2d4c6e68dbf8c76fceb99
sha256: 4280292e0cc7f6507fc901d337481b34f8a5cf9c3c964a7135b7187805e6cc20
sha512: 22ef092cfa97fb71e23a29e03bee3991f60c63c0d9fc849be66145ec2d94ff0dcabbe5126695f6b4fe5d1460d1d9e7edb64b9052fe0be0148091707c22c6b811
ssdeep: 3072:IpocVfb++Xuy7YXDxaOhlSmRpkxno3mOuT1UPKicuTZZIAZFXdKekyOI:WDZ++eNTxykkuc1U7cuTV3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cabw also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34359981
FireEyeTrojan.GenericKD.34359981
CAT-QuickHealTrojan.CKGENERIC
McAfeeRDN/Generic.grp
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusTrojan ( 0056c87c1 )
BitDefenderTrojan.GenericKD.34359981
K7GWTrojan ( 0056c87c1 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojanSpy.Win32.EMOTET.THHAEBO
F-ProtW32/Emotet.APS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyBackdoor.Win32.Emotet.cabw
AlibabaTrojan:Win32/Emotet.591eac24
ViRobotTrojan.Win32.Emotet.188416.B
RisingBackdoor.Emotet!8.514D (CLOUD)
Ad-AwareTrojan.GenericKD.34359981
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Crypt.Agent.lvqjl
DrWebTrojan.Emotet.1000
FortinetW32/Emotet.AJQ!tr
SophosTroj/Emotet-CLB
CyrenW32/Emotet.APS.gen!Eldorado
JiangminBackdoor.Emotet.qv
AviraTR/Crypt.Agent.lvqjl
MAXmalware (ai score=81)
ArcabitTrojan.Generic.D20C4AAD
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.34359981
TACHYONBackdoor/W32.Emotet.188416
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HFMZ
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THHAEBO
IkarusTrojan.Win32.Emotet
GDataTrojan.GenericKD.34359981
AVGWin32:BankerX-gen [Trj]
Qihoo-360Generic/Trojan.c2a

How to remove Backdoor.Win32.Emotet.cabw?

Backdoor.Win32.Emotet.cabw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment