Backdoor

Backdoor.Win32.Emotet.cgvx information

Malware Removal

The Backdoor.Win32.Emotet.cgvx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cgvx virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.cgvx?


File Info:

crc32: 648885A3
md5: 7c4b2e2be4e52decd2cf8e06536a3cc0
name: upload_file
sha1: 1dc040c30d6180733893a49c4f816adc94719c11
sha256: 6125ac492aef721dd6fe848cc4fcd7d521d0ea6155088472fd7f58ba8ce65261
sha512: d468dc3c92de6a25d4d258afd87197598447dc26a1d0ff15976f417cb30de16bb7bf61e82f308af971a7cdc8f657a7a8b225a9f75ba6d506af8b86f9caa0ff94
ssdeep: 12288:fk7/FTNhj7jMshXLdSi2usAXznmv9Xo5+jnB:mksdLdP2Lwm7B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Emotet.cgvx also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34375814
FireEyeTrojan.GenericKD.34375814
McAfeeEmotet-FRV!7C4B2E2BE4E5
BitDefenderTrojan.GenericKD.34375814
K7GWTrojan ( 005600261 )
CrowdStrikewin/malicious_confidence_60% (W)
F-ProtW32/Emotet.APJ
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyBackdoor.Win32.Emotet.cgvx
Ad-AwareTrojan.GenericKD.34375814
SophosTroj/Emotet-CLF
DrWebTrojan.DownLoader34.24759
EmsisoftTrojan.Emotet (A)
CyrenW32/Emotet.YRNT-5026
FortinetW32/Emotet.AJQ!tr
ArcabitTrojan.Generic.D20C8886
ZoneAlarmBackdoor.Win32.Emotet.cgvx
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ALYacTrojan.GenericKD.34375814
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32Win32/Emotet.CD
MAXmalware (ai score=83)
GDataWin32.Trojan.PSE.126CQ22
Qihoo-360Generic/HEUR/QVM41.2.4EF7.Malware.Gen

How to remove Backdoor.Win32.Emotet.cgvx?

Backdoor.Win32.Emotet.cgvx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment