Backdoor

How to remove “Backdoor.Win32.Emotet.cdtm”?

Malware Removal

The Backdoor.Win32.Emotet.cdtm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cdtm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cdtm?


File Info:

crc32: DEF0CC30
md5: 6f50dc32bbdc9fc676cbb12936b1d1db
name: upload_file
sha1: c4ef8fb349860215765657fd4c2fc4fd0cda32eb
sha256: c11ed0aea10fa328006b7009a5142502b7394621ee72eea7860948062e274dcd
sha512: 00b64b1158ab9ede8a5e6deeeaaf2e728ad5b5c1998330a9147c0f6ecb4dc0a84f27ccc321ddd80f91bb709ed3c6f243e2d328c119f37ae6b8671422977cb9e0
ssdeep: 12288:jZlyqwEmkmauSVd2R3R0EcX0euXBQsOsU3z431xVB:lm6whk90Btye1T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cdtm also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Emotet.999
MicroWorld-eScanTrojan.Agent.EVAU
FireEyeGeneric.mg.6f50dc32bbdc9fc6
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FQS!6F50DC32BBDC
MalwarebytesTrojan.Emotet
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.Agent.EVAU
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTrojanSpy.Win32.EMOTET.THHAEBO
BitDefenderThetaGen:NN.ZexaE.34186.4y0@a0H4jOjk
CyrenW32/Emotet.APV.gen!Eldorado
SymantecTrojan.Emotet
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMTHC
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Emotet.cdtm
AlibabaTrojan:Win32/Emotet.cdb4ec84
TencentMalware.Win32.Gencirc.10cde812
Ad-AwareTrojan.Agent.EVAU
F-SecureTrojan.TR/Emotet.xpsgf
ZillyaBackdoor.Emotet.Win32.1006
SophosTroj/Emotet-CLB
IkarusTrojan-Banker.Emotet
JiangminBackdoor.Emotet.re
MaxSecureTrojan.Malware.105305820.susgen
AviraTR/Emotet.xpsgf
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARK!MTB
ArcabitTrojan.Agent.EVAU
ZoneAlarmBackdoor.Win32.Emotet.cdtm
GDataTrojan.Agent.EVAU
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R348048
ALYacTrojan.Agent.Emotet
TACHYONTrojan/W32.Agent.917504.KO
CylanceUnsafe
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32Win32/Emotet.CD
RisingTrojan.Emotet!8.B95 (CLOUD)
FortinetPossibleThreat.MU
AVGWin32:Malware-gen

How to remove Backdoor.Win32.Emotet.cdtm?

Backdoor.Win32.Emotet.cdtm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment