Malware

Should I remove “Troj/Emotet-CQG”?

Malware Removal

The Troj/Emotet-CQG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CQG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Troj/Emotet-CQG?


File Info:

crc32: 6A53DB05
md5: e31f054211d55a030ec362f628ae8833
name: y2HXcGLRk4A.exe
sha1: 18202d836a5163e08c3ea28e11e422430fc9c36f
sha256: 1a59ad2fcbdba548484047fd4dc588979d51e6c0eef95e4e20b94e133d9623b5
sha512: db50b52a8f9cc1d5ef79238ebf7b6fff73a395b9d3ff8f60484b578af601d27e464eaf5b13bb887765651bfa7cee1ebb3811d7e2c7a3c982209336ee71510c8a
ssdeep: 3072:StarCik/dmeL14J8XhIcc5ovu3px5QmlILI1Fo2rKFtvfPlAx2opr6DlU:StazQdDL146Xmum3pvQmcI1qBPG9Qh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Emotet-CQG also known as:

BkavW32.EmotetDBO.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70520
FireEyeTrojan.GenericKDZ.70520
Qihoo-360Win32/Trojan.095
McAfeeRDN/Emotet
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.70520
K7GWTrojan ( 00557c3c1 )
K7AntiVirusTrojan ( 00557c3c1 )
TrendMicroTROJ_GEN.R011C0DJ620
CyrenW32/Emotet.AUC.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
AlibabaTrojan:Win32/Emotet.7dda7978
NANO-AntivirusTrojan.Win32.Emotet.hyijtd
ViRobotTrojan.Win32.Emotet.247808
Ad-AwareTrojan.GenericKDZ.70520
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/Emotet.tkrpf
DrWebTrojan.Emotet.1029
InvinceaMal/Generic-R + Troj/Emotet-CQG
McAfee-GW-EditionBehavesLike.Win32.Gupboot.dh
SophosTroj/Emotet-CQG
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.otv
AviraTR/Emotet.tkrpf
MAXmalware (ai score=81)
Antiy-AVLTrojan[Banker]/Win32.Emotet
MicrosoftTrojan:Win32/EmotetCrypt.ARJ!MTB
ArcabitTrojan.Generic.D11378
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.pef
GDataTrojan.GenericKDZ.70520
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4203524
BitDefenderThetaGen:NN.ZexaF.34298.puW@aO!oUJli
VBA32TrojanBanker.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CB
TrendMicro-HouseCallTROJ_GEN.R011C0DJ620
RisingTrojan.Emotet!1.CD07 (CLASSIC)
FortinetW32/GenKryptik.ESUM!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Troj/Emotet-CQG?

Troj/Emotet-CQG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment