Malware

VB.Heur.EmoDldr.28.3F4FCF67.Gen removal

Malware Removal

The VB.Heur.EmoDldr.28.3F4FCF67.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VB.Heur.EmoDldr.28.3F4FCF67.Gen virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine VB.Heur.EmoDldr.28.3F4FCF67.Gen?


File Info:

crc32: C9F91840
md5: aaf91a78f68396ee0754631a48cb7ac3
name: upload_file
sha1: 27fe9a59128af60d0b0438e6a7f8c384256555ad
sha256: ea3c7250737177df1b6a661ff336a738135cac3797296b684fbc4a7fbb44f8af
sha512: 65c0202ecbbc7c454e1ba219b3726443451cf2400bc69616f3559f27e7a0a4a1767c0b7d936d486cafd4bebc7048ae15a1fb94adff31576c3fa2789930d6a0b0
ssdeep: 3072:aj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGk/BAQUt45ZhwM6:aHgtEWPsL/aTyT9GkyQUtQZhwM6
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Aperiam., Author: Louna Dumas, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Aug 20 08:44:00 2020, Last Saved Time/Date: Thu Aug 20 08:44:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 19, Security: 0

Version Info:

0: [No Data]

VB.Heur.EmoDldr.28.3F4FCF67.Gen also known as:

Elasticmalicious (high confidence)
ClamAVDoc.Downloader.Emotet-9448058-0
FireEyeVB.Heur.EmoDldr.28.3F4FCF67.Gen
CAT-QuickHealOLE.Emotet.38799
McAfeeW97M/Downloader.ddv
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
TrendMicroTrojan.W97M.POWLOAD.TIOIBEMN
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.TIOIBEMN
AvastSNH:Script [Dropper]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB.Heur.EmoDldr.28.3F4FCF67.Gen
NANO-AntivirusTrojan.Script.Downloader.htfcpy
ViRobotDOC.Z.Agent.242406
MicroWorld-eScanVB.Heur.EmoDldr.28.3F4FCF67.Gen
RisingMalware.ObfusVBA@ML.97 (VBA)
Ad-AwareVB.Heur.EmoDldr.28.3F4FCF67.Gen
SophosMal/DocDl-K
F-SecureMalware.W97M/Agent.2957934
DrWebExploit.Siggen2.25215
InvinceaMal/DocDl-K
EmsisoftTrojan-Downloader.Macro.Generic.AO (A)
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.2957934
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.lgm
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ArcabitVB.Heur.EmoDldr.28.3F4FCF67.Gen
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AUK
AhnLab-V3Downloader/DOC.Emotet.S1279
ALYacTrojan.Downloader.DOC.Gen
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UCS
TencentHeur.Macro.Generic.h.c3e2df35
YandexTrojan.MacroDown.Gen.TN
FortinetVBA/Agent.K!tr.dldr
AVGSNH:Script [Dropper]
Qihoo-360virus.office.qexvmc.1065

How to remove VB.Heur.EmoDldr.28.3F4FCF67.Gen?

VB.Heur.EmoDldr.28.3F4FCF67.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment