Backdoor

Backdoor.Win32.Emotet.chhy removal guide

Malware Removal

The Backdoor.Win32.Emotet.chhy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.chhy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

How to determine Backdoor.Win32.Emotet.chhy?


File Info:

crc32: 3D8DB04A
md5: 31600cf7884c520d757150f229e47e52
name: upload_file
sha1: 343691735e24e4192c69a8cd68aa55946397afae
sha256: b9538e09690f01366469c65c8ed4cff7838f178ce6c801fe91a057f9876cea06
sha512: c1ce1438183d8c608635f57ece5c74adbe5ccb5d2a599b63600760b21ff644caa2739c8bf9c355c2eabf1400ffce988e5205f4cde6269874fac47bf0f36f036b
ssdeep: 3072:Jg0F0rmR9zx/6iJPov25dn+WMFYrIZ8fqi/nMhiIsMtk69YgTuXBiCeWLFoyBQz:g09/7Jwu5Z+WLkuItx9YFB+efci6uD9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: CTestProgressBar
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CTestProgressBar Application
ProductVersion: 1, 0, 0, 1
FileDescription: CTestProgressBar MFC Application
OriginalFilename: CTestProgressBar.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.chhy also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69517
CAT-QuickHealTrojan.CKGENERIC
Qihoo-360Win32/Backdoor.e5a
McAfeeEmotet-FRV!31600CF7884C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69517
K7GWRiskware ( 0040eff71 )
TrendMicroTrojan.Win32.WACATAC.THHAGBO
CyrenW32/Injector.ABK.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.chhy
AlibabaTrojan:Win32/Emotet.224c806d
RisingTrojan.Kryptik!1.CA97 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69517
TACHYONTrojan/W32.Agent.282624.ALP
F-SecureTrojan.TR/Emotet.yrngf
DrWebTrojan.DownLoader34.24976
Invinceaheuristic
SophosTroj/Emotet-CLE
IkarusTrojan-Banker.Emotet
F-ProtW32/Injector.ABK.gen!Eldorado
JiangminBackdoor.Emotet.rh
WebrootW32.Trojan.Gen
AviraTR/Emotet.yrngf
FortinetPossibleThreat.MU
ArcabitTrojan.Generic.D10F8D
ZoneAlarmBackdoor.Win32.Emotet.chhy
MicrosoftTrojan:Win32/Emotet.ARK!MTB
AhnLab-V3Trojan/Win32.Emotet.R348101
ALYacTrojan.GenericKDZ.69517
VBA32Trojan.Hynamer
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTrojan.Win32.WACATAC.THHAGBO
TencentMalware.Win32.Gencirc.10cde871
GDataTrojan.GenericKDZ.69517
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Backdoor.Win32.Emotet.chhy?

Backdoor.Win32.Emotet.chhy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment