Malware

What is “BAT/Filecoder.EM”?

Malware Removal

The BAT/Filecoder.EM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Filecoder.EM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Suspicious use of certutil was detected
  • Uses suspicious command line tools or Windows utilities

How to determine BAT/Filecoder.EM?


File Info:

name: EA6FC917B6A5B4F4BF23.mlw
path: /opt/CAPEv2/storage/binaries/dd3d10072397ab94a299e894011fab2bd8bc6022c350161772c7d39797a7ba43
crc32: F415FA47
md5: ea6fc917b6a5b4f4bf2309b757304b92
sha1: 0d944a69254cb014743864d83703029be585073b
sha256: dd3d10072397ab94a299e894011fab2bd8bc6022c350161772c7d39797a7ba43
sha512: 8bfe78bf99cb8630ce7408234e665114b36bd3080879cb44892b6b6a55cc5f5b9844d3c603d0998b76274e9a37a11fac6be8aadefda2e2267066f75d50de1dc3
ssdeep: 1536:b7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfLxrOn:3q6+ouCpk2mpcWJ0r+QNTBfL+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB936C41F3E241F7EAF10A7100A6712FA73667249724E8DBC34C3D829953AD59A3D3E9
sha3_384: 6a0aa0033110f706ae2a59422a5cf41e5f66163c3ff93f9caa44a2a11a6f9a3742ab952283df1e7edb7cedec55a49e4f
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

BAT/Filecoder.EM also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ea6fc917b6a5b4f4
CAT-QuickHealTrojan.GenericPMF.S17672681
CylanceUnsafe
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
Cybereasonmalicious.9254cb
VirITTrojan.Win32.Genus.IHW
ESET-NOD32BAT/Filecoder.EM
APEXMalicious
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
SophosGeneric ML PUA (PUA)
Antiy-AVLTrojan/Generic.ASMalwS.2B9EB3B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.DR6CWW
CynetMalicious (score: 100)
MalwarebytesMalware.AI.392946571
RisingTrojan.Generic@AI.98 (RDML:lppml0vBTjU9Z35m/8iSLw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen

How to remove BAT/Filecoder.EM?

BAT/Filecoder.EM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment