Backdoor

About “Backdoor.Win32.Emotet.cjqs” infection

Malware Removal

The Backdoor.Win32.Emotet.cjqs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cjqs virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.cjqs?


File Info:

crc32: B11EBEC5
md5: 4b167c8fb02db363cef31489f369d7df
name: o.exe
sha1: caa2b5e9b2d504bbd25b33a9b6f6f9ef88dd534f
sha256: cf26668f269bc1ddb15f014e0c78e0fd5a4efde2f9f19cb061408ca621b62bef
sha512: aa529b81765c8c094e9146c4c6fcaf9d0c88625646bbc7d53f3792c6c478c444b9b199dbce3fb1f78329d52c09aeac8c492fd72f1829d12becd4c3a379a26254
ssdeep: 12288:h5q4Q0ti//RlGGxk4AJbXNFJ7701hTosztGGM:Xq70o/Rljk4AdNL70/93M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001
InternalName: TestMfc
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TestMfc Application
ProductVersion: 1, 0, 0, 1
FileDescription: TestMfc MFC Application
OriginalFilename: TestMfc.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.cjqs also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43699485
FireEyeGeneric.mg.4b167c8fb02db363
CAT-QuickHealTrojan.CKGENERIC
McAfeeEmotet-FRV!4B167C8FB02D
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056cee31 )
BitDefenderTrojan.GenericKD.43699485
K7GWTrojan ( 0056cee31 )
TrendMicroTROJ_FRS.0NA103HL20
CyrenW32/Emotet.AQP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_FRS.0NA103HL20
AvastWin32:Trojan-gen
ClamAVWin.Packed.Atraps-9427203-0
KasperskyBackdoor.Win32.Emotet.cjqs
AlibabaTrojan:Win32/Emotet.d0a9bda0
NANO-AntivirusTrojan.Win32.Emotet.hsoxlg
ViRobotTrojan.Win32.Z.Emotet.790528.JM
TencentMalware.Win32.Gencirc.10cdeac8
Ad-AwareTrojan.GenericKD.43699485
TACHYONBackdoor/W32.Emotet.790528
F-SecureTrojan.TR/AD.Emotet.gblul
DrWebTrojan.Emotet.1001
ZillyaTrojan.Emotet.Win32.24749
InvinceaMal/Generic-R + Troj/Emotet-CLM
SophosTroj/Emotet-CLM
APEXMalicious
JiangminBackdoor.Emotet.rv
MaxSecureTrojan.Malware.105705876.susgen
AviraTR/AD.Emotet.gblul
Antiy-AVLTrojan/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D29ACD1D
AhnLab-V3Trojan/Win32.Emotet.R348786
ZoneAlarmBackdoor.Win32.Emotet.cjqs
GDataTrojan.GenericKD.43699485
CynetMalicious (score: 85)
VBA32TrojanBanker.Emotet
ALYacTrojan.GenericKD.43699485
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.TRE
IkarusTrojan-Banker.Emotet
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.CAD8 (CLASSIC)
YandexTrojan.Emotet!
FortinetW32/Emotet.E88D!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.0ec

How to remove Backdoor.Win32.Emotet.cjqs?

Backdoor.Win32.Emotet.cjqs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment