Malware

Troj/Emotet-CQW removal guide

Malware Removal

The Troj/Emotet-CQW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CQW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Troj/Emotet-CQW?


File Info:

crc32: 289539C6
md5: b064bdc0c8f05ff1ec3d2d1f84132cf1
name: upload_file
sha1: f4c37f265fdce6554c921d37fd9991cf9f5d45bb
sha256: 9c307eeee288fb14f044f253dc41f7e2af1854be03f08a68c3f068b341718945
sha512: 9e6dded2206e76ab3553aa8bb1fdcb327b9fec7614f1381c5702ed01f72b3a01e6eb37f10ab042b5b05796ba008a1238ca5da2bc9dd6b43d4caff5baf79d59bf
ssdeep: 12288:kTkn1g4i3Z1ba0ok3AfwlcwFP90ws7YbJmfhTXZQaLY+XbHiYD:kTyg4i3uhsP9Zs7oJmfhTpQB+XbH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001
InternalName: PictureExDemo
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: PictureExDemo Application
SpecialBuild: 6
ProductVersion: 1, 0, 0, 1
FileDescription: PictureExDemo MFC Application
OriginalFilename: PictureExDemo.EXE
Translation: 0x0409 0x04b0

Troj/Emotet-CQW also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Emotet.1041
MicroWorld-eScanTrojan.GenericKD.44089922
FireEyeGeneric.mg.b064bdc0c8f05ff1
McAfeeRDN/Emotet
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.44089922
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaE.34570.Vu0@a4ewPqpi
CyrenW32/Banker.FQ.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9778444-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
AlibabaTrojan:Win32/EmotetCrypt.bde85fc0
ViRobotTrojan.Win32.Emotet.783360
Ad-AwareTrojan.GenericKD.44089922
SophosTroj/Emotet-CQW
F-SecureTrojan.TR/AD.Emotet.goibd
InvinceaTroj/Emotet-CQW
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
EmsisoftTrojan.Emotet (A)
SentinelOneDFI – Suspicious PE
AviraTR/AD.Emotet.goibd
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/EmotetCrypt.SS!MTB
ArcabitTrojan.Generic.D2A0C242
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.GenericKD.44089922
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4206865
VBA32BScope.Malware-Cryptor.Emotet
ALYacTrojan.GenericKD.44089922
TACHYONTrojan/W32.Emotet.783360
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CI
RisingTrojan.Generic@ML.100 (RDML:THV6714wu+Igp6y9TaoRSg)
IkarusTrojan-Banker.Emotet
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/BankerX.5CC7!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.716

How to remove Troj/Emotet-CQW?

Troj/Emotet-CQW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment