Backdoor

How to remove “Backdoor.Win32.Emotet.cjqz”?

Malware Removal

The Backdoor.Win32.Emotet.cjqz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cjqz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Win32.Emotet.cjqz?


File Info:

crc32: 897C5CBE
md5: fb849c04178f352e3a7fec2dec36e7e9
name: fkdih.exe
sha1: 9bc1b9bdf4b63068cba041c19e5d36d481c9b4ab
sha256: bcab4a3cbe3bb1885b21386883e6dea4fb128eb0e8b227e2c909c9c3039df121
sha512: 99773230a5c539c0c634924b21691ac969648dda4f2247f57dbda3b4ad4d83b55a045341ffdbe77f8cf57e8d7a80cc66298ec3aa7bf99a9a7f41092b19646fec
ssdeep: 6144:TqfI2dK4las/gMXzGnZq/TVb+7/qyPoNIZAFJi:TqfIJ4lxgMXyUnskIiW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: SplitPath
FileVersion: 1, 1, 0, 0
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Anwendung SplitPath
SpecialBuild:
ProductVersion: 1, 1, 0, 0
FileDescription: MFC-Anwendung SplitPath
OriginalFilename: SplitPath.EXE
Translation: 0x0407 0x04b0

Backdoor.Win32.Emotet.cjqz also known as:

BkavW32.PhorpiexUPL.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69604
FireEyeTrojan.GenericKDZ.69604
CAT-QuickHealTrojan.CKGENERIC
Qihoo-360Generic/Trojan.952
McAfeeEmotet-FRV!FB849C04178F
ZillyaTrojan.Emotet.Win32.24751
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKDZ.69604
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Emotet.AQT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generickdz-9481059-0
KasperskyBackdoor.Win32.Emotet.cjqz
AlibabaTrojan:Win32/Emotet.fb77b583
NANO-AntivirusTrojan.Win32.Emotet.hsejql
ViRobotTrojan.Win32.Emotet.315392.B
AegisLabTrojan.Win32.Emotet.L!c
RisingTrojan.Kryptik!8.8 (TFE:5:3tSk2dAaYGU)
Ad-AwareTrojan.GenericKDZ.69604
F-SecureTrojan.TR/AD.Emotet.ichmm
DrWebTrojan.DownLoader34.26327
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DHM20
SophosTroj/Emotet-CLN
JiangminBackdoor.Emotet.sa
AviraTR/AD.Emotet.ichmm
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.PED!MTB
ArcabitTrojan.Generic.D10FE4
ZoneAlarmBackdoor.Win32.Emotet.cjqz
GDataTrojan.GenericKDZ.69604
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R348891
ALYacTrojan.GenericKDZ.69604
VBA32Trojan.Wacatac
MalwarebytesTrojan.Emotet
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R011C0DHM20
TencentMalware.Win32.Gencirc.10cdeb6c
IkarusTrojan-Banker.Emotet
FortinetW32/Kryptik.HCEJ!tr
AVGWin32:Trojan-gen
PandaTrj/Agent.AJS
MaxSecureTrojan.Malware.105705873.susgen

How to remove Backdoor.Win32.Emotet.cjqz?

Backdoor.Win32.Emotet.cjqz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment