Malware

What is “VB.Heur.EmoDldr.32.FD1C4AC1.Gen”?

Malware Removal

The VB.Heur.EmoDldr.32.FD1C4AC1.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VB.Heur.EmoDldr.32.FD1C4AC1.Gen virus can do?

  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine VB.Heur.EmoDldr.32.FD1C4AC1.Gen?


File Info:

crc32: AB9DE750
md5: d1138abd5497e1b26d6ed73fb9d5b7a1
name: upload_file
sha1: 3d06ce8d02d172c286a2833292ea32c852d13515
sha256: ed51269c3602786ff6ddef3a808d8178d26e4e5960f4ac7af765e4bd642128dd
sha512: 255a7c4ba5a390b643e02c4f8fcc517d39e995970840c8f6475429d95238181d74d12d4b2990679a5a562ace0c8e8832d7c5f2f0a2647a33d0b9fb0e9a53da48
ssdeep: 3072:JJivKie6B/w2yiWydwRglnmTEH/+Tff0JuWY:JJiP/w2PXIEf+Tf0Jun
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Recusandae., Author: Louise Fleury, Template: Normal.dotm, Last Saved By: Lucas Fernandez, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Oct 29 12:21:00 2020, Last Saved Time/Date: Thu Oct 29 12:21:00 2020, Number of Pages: 1, Number of Words: 10678, Number of Characters: 60869, Security: 8

Version Info:

0: [No Data]

VB.Heur.EmoDldr.32.FD1C4AC1.Gen also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVB.Heur.EmoDldr.32.FD1C4AC1.Gen
CAT-QuickHealW97M.Emotet.Heur
McAfeeW97M/Downloader.dha
AegisLabTrojan.MSOffice.SAgent.4!c
K7AntiVirusTrojan ( 005722491 )
K7GWTrojan ( 005722491 )
ArcabitVB.Heur.EmoDldr.32.FD1C4AC1.Gen
TrendMicroTrojan.W97M.EMOTET.TIOIBEMD
CyrenW97M/Agent.LD.gen!Eldorado
SymantecW97M.Downloader
ESET-NOD32VBA/TrojanDownloader.Agent.UFY
TrendMicro-HouseCallTrojan.W97M.EMOTET.TIOIBEMD
AvastVBS:Malware-gen
ClamAVDoc.Downloader.Generic-9785156-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB.Heur.EmoDldr.32.FD1C4AC1.Gen
TencentHeur.Macro.Generic.h.374a2410
Ad-AwareVB.Heur.EmoDldr.32.FD1C4AC1.Gen
EmsisoftTrojan-Downloader.Macro.Generic.CH (A)
ComodoTrojWare.Win32.Genome.zyyou@0
F-SecureMalware.W97M/Agent.5906912
DrWebExploit.Siggen2.60080
InvinceaTroj/DocDl-ABCF
McAfee-GW-EditionW97M/Downloader.dha
FireEyeVB.Heur.EmoDldr.32.FD1C4AC1.Gen
SophosTroj/DocDl-ABCF
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.5906912
Antiy-AVLTrojan[Downloader]/MSOffice.Agent
GridinsoftTrojan.U.Agent.oa
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ViRobotDOC.Z.Agent.233466.A
AhnLab-V3Downloader/MSOffice.Generic
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AVL
CynetMalicious (score: 85)
VBA32Trojan-Downloader.VBA.Emotet
ALYacTrojan.Downloader.DOC.Gen
RisingDownloader.Emotet/VBA!1.CE3F (CLASSIC)
FortinetVBA/Agent.BIQ!tr
AVGVBS:Malware-gen
Qihoo-360virus.office.qexvmc.1090

How to remove VB.Heur.EmoDldr.32.FD1C4AC1.Gen?

VB.Heur.EmoDldr.32.FD1C4AC1.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment