Malware

Should I remove “Generic.EmotetAC.B1D9CF5E”?

Malware Removal

The Generic.EmotetAC.B1D9CF5E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.EmotetAC.B1D9CF5E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.EmotetAC.B1D9CF5E?


File Info:

crc32: 8FCD04F2
md5: 3742e3442dd51724abedda1cf531111f
name: 3742E3442DD51724ABEDDA1CF531111F.mlw
sha1: 05ddc5a846ceb61ee3afe009d95a7c19632f0b26
sha256: 43821526a58e89b92ce091ffa9b8fb44dd7ef1fb317a66688cdacad0021c02de
sha512: 402924572058d6d22d1308cb19bc46f4ee72488da6981fea95303d7c4dd8bcebd2c37aa63c8b8c70befd4a5a64f4fe9ddb69e2ebe761cb3cb2ffa7366edea967
ssdeep: 12288:KwxxPjBUGEYtZ3uiLLrNA3HGwVI/g1fO:tLaAZ+iLLYHGwVI/a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: Formula
FileVersion: 1, 0, 0, 4
CompanyName:
LegalTrademarks:
ProductName: Anwendung Formula
ProductVersion: 1, 0, 0, 4
FileDescription: MFC-Anwendung Formula
OriginalFilename: Formula.EXE
Translation: 0x0407 0x04b0

Generic.EmotetAC.B1D9CF5E also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.EmotetAC.B1D9CF5E
FireEyeDeepScan:Generic.EmotetAC.B1D9CF5E
CAT-QuickHealTrojan.MultiRI.S16483654
Qihoo-360HEUR/QVM20.1.3A86.Malware.Gen
ALYacDeepScan:Generic.EmotetAC.B1D9CF5E
CylanceUnsafe
K7AntiVirusTrojan ( 0057169c1 )
BitDefenderDeepScan:Generic.EmotetAC.B1D9CF5E
K7GWTrojan ( 0057169c1 )
TrendMicroTrojanSpy.Win32.EMOTET.SMD4.hp
CyrenW32/Emotet.AVJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Trojan.Generic-9780587-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
Ad-AwareDeepScan:Generic.EmotetAC.B1D9CF5E
SophosTroj/Emotet-CRM
DrWebTrojan.Emotet.1043
InvinceaTroj/Emotet-CRM
McAfee-GW-EditionEmotet-FSF!3742E3442DD5
EmsisoftDeepScan:Generic.EmotetAC.B1D9CF5E (B)
IkarusTrojan-Banker.Emotet
MicrosoftTrojan:Win32/EmotetCrypt.PEF!MTB
ArcabitDeepScan:Generic.EmotetAC.B1D9CF5E
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
GDataDeepScan:Generic.EmotetAC.B1D9CF5E
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R353491
Acronissuspicious
McAfeeEmotet-FSF!3742E3442DD5
MAXmalware (ai score=81)
VBA32BScope.Malware-Cryptor.Emotet
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HGWJ
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMD4.hp
RisingTrojan.Emotet!1.CDA9 (CLASSIC)
FortinetW32/Kryptik.HEOE!tr
AVGWin32:BankerX-gen [Trj]
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Generic.EmotetAC.B1D9CF5E?

Generic.EmotetAC.B1D9CF5E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment