Backdoor

Backdoor.Win32.Emotet.ceji (file analysis)

Malware Removal

The Backdoor.Win32.Emotet.ceji is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.ceji virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian

How to determine Backdoor.Win32.Emotet.ceji?


File Info:

crc32: 83574BCA
md5: a13d719959546b6e9801bd03f2a1c284
name: ulildy5mg906792648.exe
sha1: 76ec58f90460b2de5256ad967296a2ebdb9f0b89
sha256: c7ef56ba9a8f4ddfdb7ad7e838326d4f3a888167c45cc60c230335a03df87781
sha512: 0b8f85b99ed57d20e84ee8b9bd6fa0d6db1a85dc99cfb19828082a85876e02a7baf6ba59b14c596944b0e539e1db638f66731d6722db58550afa28338eefb6a6
ssdeep: 12288:kZlyqwEmkmauSVd2R3R0EcX0euXBFsfsU3z44nbGc:6m6whk90BzyZn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.ceji also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Agent.EVAU
FireEyeGeneric.mg.a13d719959546b6e
ALYacTrojan.Agent.EVAU
BitDefenderTrojan.Agent.EVAU
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.ceji
Ad-AwareTrojan.Agent.EVAU
DrWebTrojan.Emotet.999
FortinetW32/Malicious_Behavior.VEX
SophosTroj/Emotet-CLB
IkarusTrojan.Win32.Emotet
MAXmalware (ai score=86)
ArcabitTrojan.Agent.EVAU
MicrosoftTrojan:Win32/Emotet.ARK!MTB
McAfeeEmotet-FQS!A13D71995954
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/GenKryptik.EQKW
GDataTrojan.Agent.EVAU
BitDefenderThetaGen:NN.ZexaE.34152.4y0@aWkT8Xkk
AVGFileRepMalware

How to remove Backdoor.Win32.Emotet.ceji?

Backdoor.Win32.Emotet.ceji removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment