Backdoor

What is “Backdoor.Win32.Emotet.cexg”?

Malware Removal

The Backdoor.Win32.Emotet.cexg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cexg virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cexg?


File Info:

crc32: F5D047DD
md5: d7ad0eaf7337f101b6ab7ee9a46125ac
name: upload_file
sha1: 591748dda49ddae844f1fb4550cfe6cbcb303d32
sha256: 2bc23e3b5c40d9b8d89c41840716d72a837aab12c6570c2fabb6ed48c6e1830e
sha512: aed5dc2e972d5e23a1aeceb7fe5fba9c6eb4e0e6f7753485aab7d119017786534ad9763f6c783e2e74fba790ec53b245e05b5918957bb8ffc4df58a832f7fab8
ssdeep: 12288:LZlyqwEmkmauSVd2R3R0EcX0euXBFsDsU3z44nbGc:dm6whk90BzyZn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: ExpCheckTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ExpCheckTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: ExpCheckTest MFC Application
OriginalFilename: ExpCheckTest.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cexg also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EVAU
FireEyeGeneric.mg.d7ad0eaf7337f101
Qihoo-360Generic/Trojan.357
ALYacTrojan.Agent.EVAU
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Agent.EVAU
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaE.34186.4y0@au3UEMlk
CyrenW32/Emotet.APV.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Emotet.cexg
AlibabaTrojan:Win32/Emotet.5093b8dc
ViRobotTrojan.Win32.Z.Emotet.917504.IX
TencentMalware.Win32.Gencirc.10cde812
Ad-AwareTrojan.Agent.EVAU
F-SecureTrojan.TR/Kryptik.avlcy
DrWebTrojan.Emotet.999
ZillyaBackdoor.Emotet.Win32.1006
TrendMicroTROJ_GEN.R002C0DHG20
SophosTroj/Emotet-CLB
JiangminBackdoor.Emotet.re
AviraTR/Kryptik.avlcy
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARK!MTB
ArcabitTrojan.Agent.EVAU
AhnLab-V3Trojan/Win32.Emotet.R348048
ZoneAlarmBackdoor.Win32.Emotet.cexg
GDataTrojan.Agent.EVAU
ESET-NOD32Win32/Emotet.CD
McAfeeEmotet-FQS!D7AD0EAF7337
TACHYONTrojan/W32.Agent.917504.KO
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMTHC
RisingBackdoor.Emotet!8.514D (CLOUD)
IkarusTrojan-Banker.Emotet
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.105306792.susgen

How to remove Backdoor.Win32.Emotet.cexg?

Backdoor.Win32.Emotet.cexg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment