Malware

SwBundler.Prepscram.EMU.Y7 malicious file

Malware Removal

The SwBundler.Prepscram.EMU.Y7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SwBundler.Prepscram.EMU.Y7 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine SwBundler.Prepscram.EMU.Y7?


File Info:

crc32: 26E68156
md5: 0593730cd79d29c45cd5ea9866fd1898
name: 0593730CD79D29C45CD5EA9866FD1898.mlw
sha1: 170e2d60874322bc9b174650cdb6be0caaf295ab
sha256: dfa58f81ca8a09b7f6c9649b7b159e5f6bd5514b11b339840bf5f0aebe4969f5
sha512: 11ff2d7d0f1d045e07e35f5825c16e1d47bfe7e35af0c8af4ee44fb3b67a3d820eb71060a68473467fefb2826664ed8101bf957d42aa2285288f6ae6ae975a5c
ssdeep: 12288:u37/Y4mWxgJVFpXK4cgsAwYpN1ld/wDgIJ30450a:qLJmW+LFpXK4sAzvd/wDgQ30450
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: TemplatelExeFile.rc
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: TemplatelExeFile.rc
Translation: 0x0419 0x04b0

SwBundler.Prepscram.EMU.Y7 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00528e801 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.12815
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.Prepscram.EMU.Y7
ALYacGen:Variant.ClipBanker.215
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.13631
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Kryptik.7595e34d
K7GWTrojan ( 0050eca01 )
Cybereasonmalicious.cd79d2
CyrenW32/S-4ce797cb!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.FSSN
APEXMalicious
AvastFileRepMalware
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderGen:Variant.ClipBanker.215
NANO-AntivirusRiskware.Win32.StartSurf.ephkxd
SUPERAntiSpywarePUP.Bundler/Variant
MicroWorld-eScanGen:Variant.ClipBanker.215
TencentMalware.Win32.Gencirc.10b3a151
Ad-AwareGen:Variant.ClipBanker.215
SophosGeneric PUA BH (PUA)
ComodoApplication.Win32.IStartSurf.BS@7lng48
BitDefenderThetaGen:NN.ZexaF.34628.Gy0@amzDGVak
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OB521
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.0593730cd79d29c4
EmsisoftGen:Variant.ClipBanker.215 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.fzpr
AviraHEUR/AGEN.1103317
eGambitUnsafe.AI_Score_99%
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.ClipBanker.215
AegisLabAdware.Win32.StartSurf.2!c
GDataGen:Variant.ClipBanker.215
AhnLab-V3PUP/Win32.StartSurf.R201639
Acronissuspicious
McAfeePUP-XBQ-UU
MAXmalware (ai score=80)
VBA32BScope.AdWare.StartSurf
MalwarebytesGeneric.Trojan.Bundler.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OB521
RisingTrojan.Kryptik!1.AB1C (CLOUD)
YandexTrojan.GenAsa!Oktj2z3Be/Q
IkarusAdWare.ICLoader
MaxSecureTrojan.Malware.3771246.susgen
FortinetW32/Kryptik.FTMV!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Virus.Adware.059

How to remove SwBundler.Prepscram.EMU.Y7?

SwBundler.Prepscram.EMU.Y7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment