Backdoor

Backdoor.Win32.Emotet.cjrq removal guide

Malware Removal

The Backdoor.Win32.Emotet.cjrq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.cjrq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Emotet.cjrq?


File Info:

crc32: F7B9FCA0
md5: 7c5d03d9069fe27ae8809468cf54bc47
name: SDvgrQ49wiuF2qRz.exe
sha1: 26a2eaf8d23840adcf213ea2405160fb8c038cbe
sha256: 2f8eb165ca287b1abe5d4e28c5e422f6ba9d6bb9c57f2e4f57b798b28f1c8280
sha512: 0636430958a53835723b7c5286769730016f7838855105368b0da986a74f8a8c48b7e5099c7db7a3c788c3ade999f4b62a6c815c1f00643ab46492f8942693e3
ssdeep: 3072:IRMxtgIrpwUMuN+SlId2ccld5b2IOIQlNtGZknCBNZHAr9BnZfp/adi:TxtUUMd2ccld5b2IOIQlNtGZknC/NAb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006
InternalName: oscilloscope
FileVersion: 2, 0, 0, 0
CompanyName: Waikato University
PrivateBuild:
LegalTrademarks:
Comments: Modified by Cyril COMTE
ProductName: Waikato University oscilloscope-compressor
SpecialBuild:
ProductVersion: 2, 0, 0, 0
FileDescription: oscilloscope-compressor
OriginalFilename: oscilloscope.exe->compressor
Translation: 0x1409 0x04b0

Backdoor.Win32.Emotet.cjrq also known as:

FireEyeGen:Variant.Zusy.311759
CAT-QuickHealTrojan.CKGENERIC
Qihoo-360Generic/Trojan.d51
McAfeeEmotet-FRW!7C5D03D9069F
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Small.lbIX
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Zusy.311759
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTROJ_GEN.R011C0DHN20
CyrenW32/Emotet.AQV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyBackdoor.Win32.Emotet.cjrq
AlibabaTrojan:Win32/Emotet.a695d0d4
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Zusy.311759
RisingTrojan.Emotet!1.CAFF (CLASSIC)
Ad-AwareGen:Variant.Zusy.311759
F-SecureTrojan.TR/Emotet.jtxqd
DrWebTrojan.Emotet.999
ZillyaBackdoor.Emotet.Win32.1128
SophosTroj/Emotet-CLO
IkarusTrojan-Banker.Emotet
JiangminBackdoor.Emotet.sl
AviraTR/Emotet.jtxqd
MAXmalware (ai score=89)
Antiy-AVLTrojan[Backdoor]/Win32.Emotet
MicrosoftTrojan:Win32/Emotet.PED!MTB
ZoneAlarmBackdoor.Win32.Emotet.cjrq
GDataGen:Variant.Zusy.311759
AhnLab-V3Trojan/Win32.Emotet.R349131
ALYacGen:Variant.Zusy.311759
TACHYONBackdoor/W32.Emotet.163840
VBA32Backdoor.Emotet
MalwarebytesTrojan.Emotet
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R011C0DHN20
TencentMalware.Win32.Gencirc.10cdec41
FortinetW32/Emotet.E88D!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.105705907.susgen

How to remove Backdoor.Win32.Emotet.cjrq?

Backdoor.Win32.Emotet.cjrq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment