Backdoor

Backdoor.Win32.Emotet.cenq removal instruction

Malware Removal

The Backdoor.Win32.Emotet.cenq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cenq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cenq?


File Info:

crc32: 45E314AD
md5: 0a9d1d98b6a6d810cc949499f0f152a4
name: upload_file
sha1: b51b25b22db96cee122d88e180a5ab41f2a6695b
sha256: 2318cbbd5604b29da7bf13fe31e248049a01930ef044d082f938d4ddbc7cb519
sha512: 5cbff31e4097bb2fdfc176d6f8f93060fcecd070abff855c87063b6f33f4c90cf368004bf9b2e840c8d1c694d998a0a7242b9efbbf2082388283a5d45e8a877f
ssdeep: 12288:SZlyqwEmkmauSVd2R3R0EcX0euXBzs5xsU3z4ZuF:4m6whk90Bq2yQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cenq also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.34363134
FireEyeGeneric.mg.0a9d1d98b6a6d810
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FQS!0A9D1D98B6A6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
BitDefenderTrojan.GenericKD.34363134
K7GWRiskware ( 0040eff71 )
TrendMicroTrojanSpy.Win32.EMOTET.THHAEBO
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Emotet.cenq
AlibabaTrojan:Win32/Emotet.adaaee8b
RisingBackdoor.Emotet!8.514D (CLOUD)
Ad-AwareTrojan.GenericKD.34363134
F-SecureTrojan.TR/Kryptik.lkdfh
DrWebTrojan.Emotet.999
FortinetW32/Malicious_Behavior.VEX
SophosTroj/Emotet-CLB
AviraTR/Kryptik.lkdfh
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D20C56FE
MicrosoftTrojan:Win32/Emotet.ARK!MTB
BitDefenderThetaGen:NN.ZexaE.34152.4y0@aeUzy0dk
ALYacTrojan.GenericKD.34363134
TACHYONTrojan/W32.Agent.917504.KO
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/GenKryptik.EQKW
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.THHAEBO
IkarusTrojan.Win32.Emotet
GDataWin32.Trojan-Spy.Emotet.2VSC4W
AVGWin32:Malware-gen
Qihoo-360Generic/HEUR/QVM41.2.4143.Malware.Gen

How to remove Backdoor.Win32.Emotet.cenq?

Backdoor.Win32.Emotet.cenq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment