Malware

Malware.Heuristic.3015 removal tips

Malware Removal

The Malware.Heuristic.3015 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.Heuristic.3015 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.Heuristic.3015?


File Info:

name: 518D0BF4B335EED4F8A5.mlw
path: /opt/CAPEv2/storage/binaries/ef3d70aaba49ef86d35d0df8cd911003b643133cd4a18ed496df1751196f2eb9
crc32: 22C261BB
md5: 518d0bf4b335eed4f8a51efdc64f5194
sha1: 2f246be53d5a82baaa30a19e0cc3a5cbd20cd6a5
sha256: ef3d70aaba49ef86d35d0df8cd911003b643133cd4a18ed496df1751196f2eb9
sha512: 64d1b88791fcae5373f0613f5156029800533cb94ab286c7f73c9d054b5c1c6e8c077e19ca3919333cc19e1e6f2c11835db13a4f782a81f2c0ba3f149c9e4536
ssdeep: 12288:r/ddXi4KcFjC5s4DHbr1/bWg6z2V7nDlrcUY+yLLM5mt/vZRT/9DeATGWi3o:C4Kcl4tjblAQyau/Dltq3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121055C11B551E02ED4B71AF49929CBF96D38AF612E55E8C36AC03F9D3F71982C026327
sha3_384: 313c26b5a634058d1b40482af389f261dda8150584b9f373618053f0fe247fa129d563aee6589ff6a272da0daffa0820
ep_bytes: 64a100000000558bec6aff6810334500
timestamp: 2000-11-09 05:58:53

Version Info:

CompanyName: Design Science, Inc.
FileDescription: Microsoft Equation Editor
FileVersion: 00110900
InternalName: Equation Editor
LegalCopyright: Copyright © Design Science, Inc. 1990-2000
LegalTrademarks:
OriginalFilename: EQNEDT32.EXE
ProductName: Microsoft Equation Editor
ProductVersion: 3.1
Translation: 0x0409 0x04e4

Malware.Heuristic.3015 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGeneric.mg.518d0bf4b335eed4
SkyhighBehavesLike.Win32.Backdoor.ch
McAfeeGenericRXAA-AA!518D0BF4B335
Cylanceunsafe
VIPREGen:Variant.Mint.Zard.5
SangforVirus.Win32.Senoval.V1d5
K7AntiVirusTrojan ( 005ad28b1 )
AlibabaVirus:Win32/Senoval.4c3941f9
K7GWTrojan ( 005ad28b1 )
Cybereasonmalicious.4b335e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GNNJ
AvastWin32:Patched-AWW [Trj]
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureHeuristic.HEUR/AGEN.1370060
ZillyaBackdoor.Convagent.Win32.7163
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
VaristW32/Convagent.DQ.gen!Eldorado
AviraHEUR/AGEN.1370060
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/Win32.Sinowal
MicrosoftVirus:Win32/Senoval.HNS!MTB
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
GDataWin32.Trojan.PSE.19RBXF0
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5482099
ALYacGen:Variant.Mint.Zard.5
MalwarebytesMalware.Heuristic.3015
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:/mnlWVdIIWTJYgF88khWNg)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GNNJ!tr
AVGWin32:Patched-AWW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)
alibabacloudVirus:Win/Senoval.HNS!MTB

How to remove Malware.Heuristic.3015?

Malware.Heuristic.3015 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment