Backdoor

Backdoor.Win32.Emotet.cjiy removal

Malware Removal

The Backdoor.Win32.Emotet.cjiy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cjiy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cjiy?


File Info:

crc32: C6955DEF
md5: 2373a84c7f6a2af3727b3a1a61b6c002
name: upload_file
sha1: e452563e0a7cf5bc56919f949a7be55849921a3c
sha256: 02b07f698ba0f7b2f508aeb78a3a7269ad9195dd72f3e2e45761aa118bdbb6c8
sha512: 04e541a81c4f65088a1f1587e3ca71e7bad01aaaf964df378fc5300db32885d12db9c078439eba98d3e7237c2fefda9908f8e4f80422a79a982e83f047c5aa0a
ssdeep: 1536:cWVZeBQyNRqZoidl5SYuO7aGL7QiReAWVGU9HmHDtN8YBnI:xORq6iGGaa7DReAMGVvpBI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004
InternalName: BrowseCtrlDemo
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: BrowseCtrlDemo Application
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: BrowseCtrlDemo MFC Application
OriginalFilename: BrowseCtrlDemo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cjiy also known as:

DrWebTrojan.DownLoader34.25061
MicroWorld-eScanTrojan.Agent.EVFI
FireEyeTrojan.Agent.EVFI
CAT-QuickHealTrojan.Wacatac
ALYacTrojan.Agent.EVFI
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056caa71 )
BitDefenderTrojan.Agent.EVFI
K7GWTrojan ( 0056caa71 )
TrendMicroTrojan.Win32.WACATAC.THHAGBO
CyrenW32/Emotet.APY.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.Win32.WACATAC.THHAGBO
AvastWin32:TrojanX-gen [Trj]
KasperskyBackdoor.Win32.Emotet.cjiy
AlibabaTrojan:Win32/Emotet.576e0d3f
NANO-AntivirusTrojan.Win32.Emotet.hrnuoi
ViRobotTrojan.Win32.Emotet.118784.F
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.Agent.EVFI
F-SecureTrojan.TR/Crypt.Agent.caeag
ZillyaBackdoor.Emotet.Win32.1105
SophosTroj/Emotet-CLF
IkarusTrojan-Banker.Emotet
JiangminBackdoor.Emotet.rj
AviraTR/Crypt.Agent.caeag
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Agent.EVFI
ZoneAlarmBackdoor.Win32.Emotet.cjiy
GDataTrojan.Agent.EVFI
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R348099
McAfeeEmotet-FRV!2373A84C7F6A
TACHYONBackdoor/W32.Emotet.118784.B
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.BitCoinMiner
PandaTrj/Agent.PM
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HFOM
TencentWin32.Backdoor.Emotet.Hprv
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HFMI!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.43e

How to remove Backdoor.Win32.Emotet.cjiy?

Backdoor.Win32.Emotet.cjiy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment