Backdoor

Backdoor.Win32.Emotet.cjrf removal guide

Malware Removal

The Backdoor.Win32.Emotet.cjrf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cjrf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.cjrf?


File Info:

crc32: 71577A1A
md5: 2f5e9417d62008dead100ca37f1d1564
name: MhHNM000062482.exe
sha1: 9be2daaa712be77cfd6b470ea38930462c119933
sha256: 44d4440fde89652eee2906dc31c8ca4255e4f263f649c93e12ee4696c28b7608
sha512: 69a54f67e012ca3a20de6932c58c80a80038c3a831ee9c8d8ffcd082e5d12f88debff6615b8186e0152a22b684a8f1971294224ae57329f9ee93b2f9c6fe83e9
ssdeep: 6144:c09Vywo8OWXccld5b2IOIQlNtGZknCdUsqCG:cYuLMG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006
InternalName: oscilloscope
FileVersion: 2, 0, 0, 0
CompanyName: Waikato University
PrivateBuild:
LegalTrademarks:
Comments: Modified by Cyril COMTE
ProductName: Waikato University oscilloscope-compressor
SpecialBuild:
ProductVersion: 2, 0, 0, 0
FileDescription: oscilloscope-compressor
OriginalFilename: oscilloscope.exe->compressor
Translation: 0x1409 0x04b0

Backdoor.Win32.Emotet.cjrf also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKDZ.69610
FireEyeTrojan.GenericKDZ.69610
CAT-QuickHealTrojan.CKGENERIC
ALYacTrojan.GenericKDZ.69610
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Emotet.L!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69610
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R011C0DHM20
CyrenW32/Emotet.AQQ.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Emotet-9481137-0
KasperskyBackdoor.Win32.Emotet.cjrf
AlibabaTrojan:Win32/Emotet.5d9fd05a
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Emotet.204800.F
TencentMalware.Win32.Gencirc.10cdee38
Ad-AwareTrojan.GenericKDZ.69610
F-SecureTrojan.TR/Emotet.wcouj
DrWebTrojan.DownLoader34.26502
ZillyaTrojan.Emotet.Win32.24758
InvinceaMal/Generic-R + Troj/Emotet-CLO
MaxSecureTrojan.Malware.105705896.susgen
SophosTroj/Emotet-CLO
IkarusTrojan-Banker.Emotet
JiangminBackdoor.Emotet.sb
AviraTR/Emotet.wcouj
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
ArcabitTrojan.Generic.D10FEA
ZoneAlarmBackdoor.Win32.Emotet.cjrf
GDataTrojan.GenericKDZ.69610
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R348876
McAfeeEmotet-FRV!2F5E9417D620
TACHYONBackdoor/W32.Emotet.204904
VBA32Backdoor.Emotet
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R011C0DHM20
RisingTrojan.Kryptik!8.8 (TFE:5:4gyYUlpXDkN)
FortinetW32/Zenpak.AUSL!tr
AVGWin32:Trojan-gen
PandaTrj/Agent.PM
Qihoo-360Win32/Backdoor.6dc

How to remove Backdoor.Win32.Emotet.cjrf?

Backdoor.Win32.Emotet.cjrf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment