Backdoor

Backdoor.Win32.Emotet.cdqv removal guide

Malware Removal

The Backdoor.Win32.Emotet.cdqv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cdqv virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cdqv?


File Info:

crc32: 26072499
md5: 9356603207485fbce9eecbc227e6ec46
name: upload_file
sha1: b1155eb34f4a80edd30fc4082f48b17effe9e587
sha256: 0205229342901b9fa39108068d025503b9caaa56f643946f29318e46df51d7c1
sha512: 36752c9374a4cd4bc81e1982b231d625caf1d961ca974ab82adba3c49b624f6ece4de52f981272da02f21fab49f9e38fe90c4cb8587720a90ab1e1694d326fb1
ssdeep: 12288:fgBPA27vorE7ed3r5WTgOPshsU3z44nbGc:tevoaErsTN9yZn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cdqv also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Emotet.1000
MicroWorld-eScanTrojan.GenericKDZ.69472
FireEyeGeneric.mg.9356603207485fbc
CAT-QuickHealTrojan.IGENERIC
McAfeeEmotet-FRV!935660320748
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69472
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.Zextet.34196.Yy0@a0lL!Dmk
CyrenW32/Emotet.APV.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyBackdoor.Win32.Emotet.cdqv
AlibabaTrojan:Win32/Emotet.9a00e737
NANO-AntivirusTrojan.Win32.Emotet.hrzmqm
ViRobotTrojan.Win32.Z.Emotet.823296.ADF
RisingTrojan.Kryptik!1.CA81 (CLOUD)
Ad-AwareTrojan.GenericKDZ.69472
TACHYONBackdoor/W32.Emotet.823296.B
F-SecureTrojan.TR/Kryptik.yoivc
ZillyaBackdoor.Emotet.Win32.1029
TrendMicroTrojanSpy.Win32.EMOTET.THHAEBO
SophosTroj/Emotet-CLB
IkarusTrojan-Banker.Emotet
GDataTrojan.GenericKDZ.69472
JiangminBackdoor.Emotet.rd
MaxSecureTrojan.Malware.105306120.susgen
AviraTR/Kryptik.yoivc
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Generic.D10F60
ZoneAlarmBackdoor.Win32.Emotet.cdqv
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R347919
ALYacTrojan.GenericKDZ.69472
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HFPB
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THHAEBO
TencentMalware.Win32.Gencirc.10cde861
FortinetPossibleThreat.MU
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.151

How to remove Backdoor.Win32.Emotet.cdqv?

Backdoor.Win32.Emotet.cdqv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment