Malware

Troj/Emotet-CQV removal instruction

Malware Removal

The Troj/Emotet-CQV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CQV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Emotet-CQV?


File Info:

crc32: 4655B4DB
md5: b751ad3e1f8e804f9fd8d1c7e2f4cb27
name: upload_file
sha1: 0ded388213fc6b2a23bcd4ad9e9e5acbb400dc22
sha256: 4a73de4827301fa3fd2c0c79f571f906da160930655686e6e5fb82b39bd04e38
sha512: 73c4667604d334d6a835131dc848b00b666d2d16ec774e34083d8eb8f482f38d2d801b76a6b28917ac5024046bdb2fe526a7d33092ef454593ba9e42c30fe90b
ssdeep: 12288:QCeRhmZzvXDrcmacsitPbD5bZy6dFDHvTzT29cq:dFvXvfumVLP29cq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: MultiSubButton
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MultiSubButton Application
ProductVersion: 1, 0, 0, 1
FileDescription: MultiSubButton MFC Application
OriginalFilename: MultiSubButton.EXE
Translation: 0x0409 0x04b0

Troj/Emotet-CQV also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34787992
FireEyeGeneric.mg.b751ad3e1f8e804f
ALYacTrojan.Agent.Emotet
BitDefenderTrojan.GenericKD.34787992
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Emotet.AUT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Generic-9778219-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
AlibabaTrojan:Win32/Emotet.b5010119
RisingTrojan.Generic@ML.84 (RDMK:C71H8xxB+xdDUSvkomm+wg)
Ad-AwareTrojan.GenericKD.34787992
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/Emotet.vgikf
DrWebTrojan.DownLoader35.1266
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S + Troj/Emotet-CQV
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SophosTroj/Emotet-CQV
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.oxv
AviraTR/Emotet.vgikf
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/EmotetCrypt.PEF!MTB
ArcabitTrojan.Generic.D212D298
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataTrojan.GenericKD.34787992
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R353278
Acronissuspicious
McAfeeEmotet-FSF!B751AD3E1F8E
VBA32BScope.Malware-Cryptor.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CI
TencentWin32.Trojan-banker.Emotet.Peyz
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.11417434.susgen
FortinetW32/BankerX.5CC7!tr
BitDefenderThetaGen:NN.ZexaF.34570.Cu0@a8K9Seai
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.213fc6
Paloaltogeneric.ml

How to remove Troj/Emotet-CQV?

Troj/Emotet-CQV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment