Защитник Windows напугал сисадминов ложным обнаружением Emotet
Microsoft Defender for Endpoint блокирует открытие файлов и выдает ошибку, указывающую на активность, связанную с Win32/PowEmotet.
Защитное решение Microsoft Defender for Endpoint блокировало открытие документов Microsoft Office и запуск некоторых исполняемых файлов из-за ложного срабатывания тега, который помечает файлы как потенциально содержащие вредоносное ПО Emotet.
Cогласно сообщениям в Twitter и на Reddit , предупреждения появились после обновления определений корпоративной платформы безопасности оконечных точек Microsoft (ранее известной как Microsoft Defender ATP) до версии 1.353.1874.0.
При срабатывании Microsoft Defender for Endpoint блокирует открытие файла и выдает ошибку, указывающую на подозрительную активность, связанную с Win32/PowEmotet.SB или Win32/PowEmotet.SC. Проблема затрагивает файлы Excel и любого приложения Microsoft Office, использующего MSIP.ExecutionHost.exe и splwow64.exe.
Microsoft не предоставила какую-либо информацию о причинах данной ситуации. Наиболее вероятная причина заключается в том, что компания в последних обновлениях усилила чувствительность защитного решения к обнаружению поведения, подобного Emotet.
Изменение, вероятно, было вызвано недавним « возрождением » ботнета Emotet две недели назад. Напомним, исследователи в области кибербезопасности из Cryptolaemus, GData и Advanced Intel выявили случаи, когда вредоносная программа TrickBot устанавливала на зараженные устройства загрузчик для Emotet.
Как сообщили специалисты Microsoft, они устранили проблему для пользователей, подключенных к облачным сервисам, и работают над исправлением для всех остальных.
Microsoft Defender напугал сисадминов ложноположительными срабатываниями на Emotet
По информации Bleeping Computer, в конце ноября системные администраторы стокнулись с ложноположительными срабатываниями корпоративной версии Microsoft Defender. Антивирусное ПО начало массово блокировать пользовательские файлы с пояснением, что обнаружена активность, связанная со зловредом Win32/PowEmotet.SB или Win32/PowEmotet.
Инцидент коснулся почти всех пользовательских файлов Excel и любого приложения Microsoft Office, которое задействовало приложения MSIP.ExecutionHost.exe и splwow64.exe.
Эксперты Bleeping Computer выяснили, что проблема появилась после получения последнего обновления платформы безопасности оконечных точек Microsoft (Defender ATP).
Через некоторое время после многочисленных жалоб пользователей Microsoft исправила в своем облачном сервисе эту проблему и пообещала выпустить заплатку, которая отключит уведомления и блокировку файлов со стороны Microsoft Defender по этому инциденту.
Пример ложноположительного срабатывания Microsoft Defender на вероятное поведение после заражения ботнетом Emotet.
How to Remove Behavior:Win32/PowEmotet.SB?

Behavior:Win32/PowEmotet.SB has been detected as a dangerous Trojan horse. Being a complicated threat, Behavior:Win32/PowEmotet.SB plays much cunning and stubborn a role on the targeted computer. By deploying a number of infected files, memory space will be largely taken that it leads computer into slow performance. It may even freeze up the operating system and shut it down randomly.
For most of the cases, users are out of awareness how Behavior:Win32/PowEmotet.SB comes into computer surreptitiously without any consent. As a result, the things utilized by Behavior:Win32/PowEmotet.SB to get inside computer can be concluded as spam email, malicious link, porn site, game, free downloading program and other malware. It is better to keep close attention on any of unfamiliar resources.
From the time it is in, Behavior:Win32/PowEmotet.SB will start resetting the keys on registry entry to make sure itself to be activated automatically together with the Windows. Hiding on computer, it is very likely for Behavior:Win32/PowEmotet.SB to exploit backdoor access for other malware to come and further destroy system files as well as programs. Seriously, Behavior:Win32/PowEmotet.SB has the ability to record your network operation and steal personal information to the cyber crook. Hence, for the prevention of driving computer into severe situation, users need to get rid of Behavior:Win32/PowEmotet.SB soon once upon the detection.
How to Remove Behavior:Win32/PowEmotet.SB? (Windows + Mac OS)
Quick Menu
Section A – Behavior:Win32/PowEmotet.SB Removal Steps For Windows OS
Section A – Behavior:Win32/PowEmotet.SB Removal Steps For Windows OS
( NOTE – Please bookmark this page first, because some steps will require you to restart your web browser or computer. )
Step 1. End malicious process run by Behavior:Win32/PowEmotet.SB and related malware.
1. Hit Ctrl + Shift + Esc keys at the same time to open Windows Task Manager:

2. Find malicious process related with Behavior:Win32/PowEmotet.SB or malware, and then right-click on it and click End Process or End Task.

Step 2. Uninstall malicious programs related with Behavior:Win32/PowEmotet.SB.
Press “Win + R ” keys together to open the Run screen;

Type control panel in the Run window and click OK button;

In Control Panel, click Uninstall a program under Programs;

Look for malicious app related with Behavior:Win32/PowEmotet.SB; Right-click on the malicious program and click Uninstall.

Many malware may re-install themselves multiple times if you don’t delete thier core files. To get rid of Behavior:Win32/PowEmotet.SB completely, we recommend downloading SpyHunter Aniti-malware to scan entire system and delete all malicious files .
Free Remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read our EULA, Privacy Policy, Cookie Policy . See more Free SpyHunter Remover details.
Step 3. Delete extension installed by Behavior:Win32/PowEmotet.SB and related malware.
Chrome
On Chrome
Click the Chrome menu button >> Click Tools >> Select Extensions:

Find extension that may be related with Behavior:Win32/PowEmotet.SB or potential threat >> Click the trash can icon to delete them.

Microsoft Edge
On Microsoft Edge
Start Edge: Click the More (…) button ahe tog right corner and click Extensions:

Select the extensions you want to remove and click Remove:


Firefox
On Firefox
Click the menu button and choose Add-ons. The Add-ons Manager tab will open.

In the Add-ons Manager tab, select the Extensions panel >> find extension that may be related with Behavior:Win32/PowEmotet.SB or potential threat >> Click Remove button.

On Internet Explorer
Open the IE, click the Tools button , and then click Manage add-ons.

Choose Toolbars and Extensions on left side of the window >> Find extension that may be related with Behavior:Win32/PowEmotet.SB or potential threat>> Click Disable button

Malicious extensions may re-install itself on web browser if you don’t delete core files of Behavior:Win32/PowEmotet.SB and related malware. To get rid of Behavior:Win32/PowEmotet.SB completely, we recommend downloading SpyHunter Aniti-malware to scan entire system and delete all malicious files .
Free Remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read our EULA, Privacy Policy, Cookie Policy . See more Free SpyHunter Remover details.
Step 4. Remove malicious files created by Behavior:Win32/PowEmotet.SB or related malware.
1. Hit Windows + R keys at the same time to open Run window and input a regedit and click OK:


2. In the Registry Editor, hit Windows key + F key together to open Find window → Enter virus name → Press Enter key to start search.

3. When the search is completed, right click the folders related with Behavior:Win32/PowEmotet.SB and click Delete button:

Please Read This Before You Remove Registry Files
PLEASE Be Carefully, Do Not Delete Healthy Registry Entries, Or Your Computer May Be Damaged.
If you are not able to determine which regsitry files are malicious, we recommend downloading SpyHunter Anti-malware to scan entire system and find out all malicious files. It can avoid mistakes and may reduce the cleanup time from hours to minutes.
Free Remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read our EULA, Privacy Policy, Cookie Policy . See more Free SpyHunter Remover details.
Step 5. Reset Web Browsers to remove Hijackers Brought by Behavior:Win32/PowEmotet.SB.
Chrome
Reset Chrome:
- Click the Chrome menu button, represented by three horizontal lines;
- Click Settings when the drop-down menu appears;
- In the Settings screen, scroll to the bottom of the page and click on the “Advanced” link;
- Click on the “Reset settings to their original defaults” button.
- A confirmation dialog appears, click on the “Reset Settings” button.
Reset Microsoft Edge:
- Click on Microsoft Edge’s main menu button, represented by three horizontal dots;
- Click on “Settings“ button when the drop-down menu appears;
- Click on “Reset Settings”On the left side of the window;
- Click on “Restore settings to their default values”
- Click on the “Reset” button in the new confirmation window that opens.
Firefox
Reset Firefox:
- Click the menu button of firefox, represented by three horizontal lines;
- Click on “Help“ button when the drop-down menu appears;
- Click on “Troubleshooting Information“ from the Help menu;
- Click the “Refresh Firefox” button in the upper-right corner of the “Troubleshooting Information” page.
- Click on the “Refresh Firefox” button in the new confirmation window that opens.
Reset IE :
- Open Internet Explorer, click on the gear icon in the upper-right part of your browser, then select “Internet Options“.
- Now select the “Advanced” tab, then click on the “Reset” button
- In the “Reset Internet Explorer settings” section, select the “Delete personal settings” checkbox, then click on the “Reset” button.
NOTE – If the steps above doesn’t help, please rescan entire infected PC with Spyhunter anti-malware and let it help you fix all problems.
Section B – Behavior:Win32/PowEmotet.SB Removal Steps For Mac OS
Step 1 – Remove nasty extension and browser hijacker related with Behavior:Win32/PowEmotet.SB or malware.
Chrome
– Click the setting button “≡” at the top right of the browser window, choose “More Tools” and choose “Extensions“.

– Click the “trash can icon” button to remove extension related with Behavior:Win32/PowEmotet.SB or malware:

Safari
Safari:
– Choose Safari > Preferences

– On the ‘Extensions’ tab, find out the extension related with adware or hijacker and click Uninstall or Disable

Firefox
Mozilla Firefox:
– Click the settings button (three horizontal bars) in the top-right corner and then select ‘Add-ons’.

– Click “Extensions” tab under Add-on Manager page to view the extensions.
– Find the suspicious add-on you want to disable and click its “Disable” button.
– If you want to delete an extension entirely, click “Remove.”

Malicious browser extensions hijack your Google Search and redirect you to unwanted websites. To get rid of related search hijacker, you need to delete core files of Behavior:Win32/PowEmotet.SB and related malware. We recommend downloading SpyHunter Mac Antimalware to remove all malicious apps and hijacker for you. This may save you hours and ensure you don’t make mistakes that harm your system
Free Remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read our EULA, Privacy Policy, Cookie Policy . See more Free SpyHunter Remover details.
Step 2 – Uninstall harmful Apps related with Behavior:Win32/PowEmotet.SB or malware
– Open Finder at the Dock

– Select Applications and find out suspicious apps related with Behavior:Win32/PowEmotet.SB , then right click on the app and click Move to Trash:

– Right click on Trash icon to select Empty Trash

Step 3 – Remove malicious files generated by Behavior:Win32/PowEmotet.SB or malware from your Mac
Malware geneates lots of malicious files and folders on infected Mac, to avoid Behavior:Win32/PowEmotet.SB reinstalling itself, you need to find out and remove all malicious files:
1. Click the Finder icon from the menu bar >> choose “Go” then click on “Go to Folder“:

2. In the Go to Folder… bar, type “/Library/LaunchAgents” and click Go:

3. In LaunchAgents folder, search for any recently-added suspicious files and move them to the Trash.

Here are some examples of files generated by malware:
“installmac.AppRemoval.plist”, “com.genieo.completer.download.plist” “com.genieoinnovation.macextension.plist” “com.genieo.engine.plist” “com.adobe.fpsaud.plist” , “myppes.download.plist”, “mykotlerino.ltvbit.plist”
4.Repeat the process on the following folders:

/Library/Application Support

/Library/LaunchDaemons

Many malware may re-install themselves multiple times if you don’t delete thier core files. To find and remove all malicious files , We recommend downloading SpyHunter Mac Antimalware to scan your Mac. This may save you hours and ensure you don’t make mistakes that harm your system
Free Remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read our EULA, Privacy Policy, Cookie Policy . See more Free SpyHunter Remover details.
Step 4 – Download SpyHunter Antimalware For Mac to Scan For Malicious Apps and Files.
Lots of Malware keep generating malicious files on infected computer deeply, thus it’s quite difficult for common computer users to find out and remove all harmful items related with Behavior:Win32/PowEmotet.SB. Meanwhile, there will be possibility that users remove core system files by mistake and then the entire computer will be harmed seriously.
To avoid the risks, We recommend all users downloading SpyHunter Antimalware For Mac, a professional automatic malware removal tool which keeps your Mac away from virus and malware attack and avoid online spam and phishing websites and protect your privacy and files well.
1. Click Download button here to download SpyHunter For Mac :
(Free Remover allows you, subject to a 48-hour waiting period, one remediation and removal for results found. Read itsEULA, Privacy Policy See more Free SpyHunter Remover details.)
2. Double-click SpyHunter-1.2-15-7043-Installer.dmg to install Spyhunter For Mac:

3. Once SpyHunter For Mac is installed, run a scan and register its full version to remove all malicious objects on your Mac.
How to Remove Win32/PowEmotet.SB (Quick & Easy Guide!)

The Win32/PowEmotet.SB virus can infiltrate your PC without you knowing. Generally, this virus enters the user system through downloading from suspicious websites and opening spam emails This malware can steal personal data and turn off the security of your system to inflict more damage. Continue reading as we discuss this virus in detail and how to remove it from your PC.
Are you short on time and looking for the easiest way to remove this malware? Spy Hunter is an effective option for removing the Win32/PowEmotet.SB automatically. This antimalware tool detects and deletes malware while also safeguarding your PC against future security threats.
Is Win32/PowEmotet.SB Malware or False Positive?
Win32/PowEmotet.SB is malware that contaminates files downloaded from dubious sources like software piracy sites and torrents. The malware can also be attached to spam emails sent by hackers. As a result, we suggest not downloading files from untrustworthy sources. To avoid the possibility of infection with Win32/PowEmotet.SB, users should scan any files or emails before opening them.
- Retrieves and sends sensitive data from the infected PC to the hacker’s system.
- Turn off security programs such as firewalls and anti-virus software.
- Downloads more malware from a remote server.
Automatic Way to Remove Win32/PowEmotet.SB
SpyHunter is our first choice for automatically removing the Win32/PowEmotet.SB virus. Here’s how to use SpyHunter to automatically remove this malware.
Step 1: Go to the SpyHunter download page and get the malware remover. Locate and click on the downloaded SpyHunter file once it has finished downloading.
Step 2: Click “Yes” when the “User Account Control” dialog pops up.
Step 3: On the following page, choose your preferred language. Then, read and accept the “License Agreement.”

Step 4: Afterward, select “Next” and complete the installation wizard.
Step 5: Then, launch the SpyHunter program and click “Start Computer Scan Now” to scan the computer. When the scan is finished, click “Remove” to get rid of the malware.
The Most Advanced Guide to Remove Win32/PowEmotet.SB Manually (Proceed with Caution!)
If you decide to remove malware manually, follow our step-by-step guide below. Note that this process takes 20-30 minutes and requires some technical skills. If you do not follow our steps carefully, this may damage or corrupt your Windows system, and you will end up paying more to reinstall the system and recover your data than getting malware removal software in the first place.
Before Proceeding to Solutions, You Need to Enter a Safe Mode
Step 1. Search for ‘Recovery Options‘ > Recovery > Advanced start-up > Restart now

Step 2. Then in Choose an option menu go to Troubleshoot > Advanced options > Startup Settings > Restart
Step 3. Once restarted, select Safe Mode with Networking and press Enter
Now let’s proceed to malware removal steps… Please follow our exact order of solutions to have a higher chance of success.
Solution #1 – Delete Suspicious Tasks in Task Scheduler
Step 1. Go to Control Panel > Administrative Tools > Task Scheduler
Step 2. Open the Task Scheduler Library folder and delete suspicious tasks

Delete suspicious tasks in Task Scheduler / Image credit: Pigtou
TIP: if you don’t recognize suspicious tasks, filter by ‘Created’ date and check the latest created tasks. Also, suspicious tasks might have a missing Author.
Solution #2 – Delete Suspicious Programs in Programs and Features
Step 1. Go to Control Panel > Programs and Features

Open Programs and Features / Image credit: Pigtou
Step 2. Sort by ‘Installed On‘ date and delete suspicious programs

Delete suspicious programs in Programs and Features / Image credit: Pigtou
TIP: Think about what programs were installed just before your PC got infected.
Solution #3 – Delete Suspicious Files from Task Manager
Step 1. Open Task Manager and go to the Details tab
Step 2. Search for suspicious processes
Step 3. Right-click on suspicious process > Open file location, and delete the file or whole folder
Delete suspicious processes in Task Manager / Image credit: Pigtou
Step 4. Get back to Task Manager and end the suspicious process
Step 5. Then search the Startup tab for suspicious processes > Open the file location, and delete the file or whole folder
Delete suspicious startup processes / Image credit: Pigtou
TIP: If ‘Access is denied’ and you’re unable to delete files, search for Resource Monitor (run as administrator), open and end the process in the Overview tab, then try to delete a file.
Solution #4 – Delete Suspicious Registries from Registry Editor
Step 1. Open Registry Editor (Run as administrator)

Run Registry Editor as administrator / Image credit: Pigtou
Step 2. Delete suspicious registries from:
Computer\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Computer\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce locations
Delete suspicious records in Run and RunOnce locations / Image credit: Pigtou
Step 3. Then select Computer and go to Edit > Find, and search Registry by names of suspicious files you remember from previous steps
Search for suspicious records / Image credit: Pigtou
TIP: You can easily delete suspicious registries from Run and RunOnce folders, however, be careful with deleting registries from other folders. This can break your system.
Solution #5 – Disable Suspicious Services in System Configuration
Step 1. Search for Run and type msconfig, then open the Services tab

Type msconfig in Run / Image credit: Pigtou
Step 2. Tick ‘Hide all Microsoft services‘

Disable suspicious services in System Configuration / Image credit: Pigtou
Step 3. Then search a list for suspicious services and untick them
TIP: Missing or unknown Manufacturer can be a good sign of suspicious service
Solution #6 – Delete Temporarily Files
Step 1. Search for Run and type %temp%

Locate Temp folder and delete everything inside / Image credit: Pigtou
Step 2. Delete everything in the Temp folder
Step 3. Empty Recycle Bin
TIP: all temporary files can be deleted without hesitation. It will not damage your system.
Solution #7 – Check Hosts File
Step 1. Go to C:\Windows\System32\drivers\etc, and open the hosts file as Notepad
Step 2. Delete everything below ‘# ::1 localhost‘

Delete suspicious records in Hosts file / Image credit: Pigtou
TIP: If a record doesn’t have ‘#’, this is definitely a suspicious record that should be deleted.
Solution #8 – Clean Browsers
Step 1. Search for your browser, right-click and open file location
Step 2. Then right-click on the browser icon and open Properties
Step 3. Delete everything after exe” in Target (for example, Google Chrome’s target should end with chrome.exe”)

Verify Target in browser properties / Image credit: Pigtou
Then you need to open your browser, delete suspicious extensions, notifications, and reset settings to defaults.
• Google Chrome:
Delete suspicious extensions: Settings > Extensions

Delete suspicious extensions in your browsers / Image credit: Pigtou
Remove suspicious notifications: Settings > Privacy and security > Notifications, then remove suspicious notifications under ‘Allowed to send notifications‘
Reset settings to defaults: Settings > Reset and clean up > Restore settings to their original defaults > Reset settings
• Mozilla Firefox:
Delete suspicious add-ons: Menu > Add-ons and themes
Remove suspicious notifications: Menu > Privacy & Security > Notifications > Settings…, then remove websites you do not want to receive notifications from
Reset settings to defaults: Menu > Help > More troubleshooting information > Refresh Firefox > Refresh Firefox
• Opera:
Delete suspicious extensions: Click on Opera icon > Extensions > Extensions
Remove suspicious notifications: Click on Opera icon > Settings > Advanced > Privacy & security > Site Settings > Notifications, then under ‘Allowed to send notifications’ remove websites you do not want to receive notifications from
Reset settings to defaults: Click on Opera icon > Update and recovery > Recover
• Microsoft Edge:
Delete suspicious extensions: Menu > Extensions
Remove suspicious notifications: Menu > Settings > Cookies and site permissions > Notifications, then under ‘Allow‘ remove websites you do not want to receive notifications from
Reset settings to defaults: Menu > Settings > Reset settings > Restore settings to their default values > Reset
Solution #9 (Optional) – Follow This Solution if Your Browser Does Not Open Any Websites
If your browsers do not open any websites while other software can connect to the internet properly, you need to check internet properties:
Step 1. Go to Control Panel > Internet Options > Connections > LAN settings

Open LAN settings / Image credit: Pigtou
Step 2. Tick ‘Automatically detect settings’ and untick ‘Use a proxy server for your LAN’

Disable proxy server for LAN / Image credit: Pigtou
Step 3. Then disable proxy servers in the browser if connection wasn’t restored yet
• Check AppInit_DLL in Registry
Step 1. Open Registry Editor (Run as administrator)
Step 2. Go to Edit > Find, search for AppInit_DLLs
Step 3. Open the AppInit_DLLs file and make sure Value Data is empty (don’t remove records starting with “SYS:”)
Check Value Data in AppInit_DLL / Image credit: Pigtou
Step 4. If Value Data contains a path to any DLL file, follow that path, find and delete that DLL file, and clean Value Data in AppInit_DLLs file.
TIP: DLL file may be hidden in the destination folder. In that case, change the folder setting by going to View > Options > Change folder and search options > View, then select ‘Show hidden files, folders and drives’
• Check DNS servers
Step 1. Go to Control Panel > All Control Panel Items > Network and Sharing Centre, then click on your Connection

Find your connection / Image credit: Pigtou
Step 2. Open Properties > Internet Protocol Version 4 (TCP/IPv4)
Step 3. Select ‘Use the following DNS server addresses’ and enter 8.8.8.8 to Preferred DNS server and 8.8.4.4 to Alternative DNS server
Update DNS servers / Image credit: Pigtou
Step 4. Then open Command Prompt and enter the following commands: ipconfig /flushdns then route –f (these commands will clean DNS cache)
Flush DNS cache / Image credit: Pigtou
Solution #10 (Optional) – Restore the Windows
If the steps above do not remove malware, you can restore your Windows to the earlier point. This will not affect your pictures, documents or personal data, but some programs or drivers might be uninstalled.
Search for Create a restore point > System Restore… > Next > Select a date you want to restore your system to > Next > Finish

Restore system to the earlier settings / Image credit: Pigtou
Conclusion
The Win32/PowEmotet.SB virus can be damaging to your computer. This virus can disable your system’s defenses and download more malware to your computer. That’s why it is essential to remove this malware using the methods provided in this article. We recommend using Spy Hunter to remove this malware quickly and automatically.
FAQs
Fortunately, this malware can be quickly removed from your computer with Spy Hunter. You can also make use of our manual removal methods.
This virus typically comes from files downloaded from untrustworthy websites and spam mail. The malware activates once the files or emails are executed. As a result, ensure you only visit trustworthy websites and scan the files and emails you download before opening them.