Backdoor

Backdoor.Win32.Emotet.cjpk removal instruction

Malware Removal

The Backdoor.Win32.Emotet.cjpk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cjpk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cjpk?


File Info:

crc32: 1B3CC8E7
md5: 74a31afb6755c167e33d96dc16673ff0
name: k0z92i46i.exe
sha1: 8ebe2c1663b8906df57c15fa2236bee52fdf850e
sha256: 024bc0e604be666396f12254ca4814a117bd31a63f20dde85859d9eb6d6e5b43
sha512: 2c1729ba598894ae789a2ff7f0160ec0d8011837ce12178e35ca5988d9db3eaa0bcfc058533f80f5dc9d7c48d3e5e62baec9024fd08eb4c843ef0f308a932f6b
ssdeep: 6144:UrI7BEw327/57jp+S/5w4fy0ElPsvN9octJ5OMJAuFZwb+NlNkvDQE8h3t:j7BEz57j2p0sPsvN9o8Vf0DQz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003 Joon-ho Ryu
InternalName: CBitmapSlider Demo
FileVersion: 1, 5, 0, 0
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: CBitmapSlider Demo Application
SpecialBuild:
ProductVersion: 1, 5, 0, 0
FileDescription: CBitmapSlider Demo MFC Application
OriginalFilename: CBitmapSlider Demo.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cjpk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69564
FireEyeGeneric.mg.74a31afb6755c167
CAT-QuickHealTrojan.CKGENERIC
McAfeeRDN/Emotet
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69564
K7GWRiskware ( 0040eff71 )
F-ProtW32/Emotet.AQI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.cjpk
AlibabaTrojan:Win32/Emotet.c950d8d2
ViRobotTrojan.Win32.Emotet.594032
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKDZ.69564
F-SecureTrojan.TR/AD.Emotet.hyhjb
DrWebTrojan.Emotet.999
TrendMicroTROJ_GEN.R002C0DHK20
FortinetW32/Kryptik.HCEJ!tr
SophosTroj/Emotet-CLJ
CyrenW32/Emotet.AQI.gen!Eldorado
JiangminBackdoor.Emotet.ru
AviraTR/AD.Emotet.hyhjb
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D10FBC
ZoneAlarmBackdoor.Win32.Emotet.cjpk
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
BitDefenderThetaGen:NN.Zextet.34186.Kq1@aqLnXsji
ALYacTrojan.GenericKDZ.69564
MalwarebytesTrojan.Emotet
ESET-NOD32a variant of Win32/Kryptik.HFPN
TrendMicro-HouseCallTROJ_GEN.R002C0DHK20
TencentWin32.Backdoor.Emotet.Ahyh
IkarusTrojan-Banker.Emotet
GDataWin32.Trojan.PSE.1UYQ3C0
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
Qihoo-360Generic/Trojan.85d

How to remove Backdoor.Win32.Emotet.cjpk?

Backdoor.Win32.Emotet.cjpk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment