Malware

What is “OLE.Emotet.38776”?

Malware Removal

The OLE.Emotet.38776 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OLE.Emotet.38776 virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine OLE.Emotet.38776?


File Info:

crc32: AB83AFE8
md5: 8dbf45bc2773c09f42e0a00d290ce41c
name: upload_file
sha1: 3a8521e0abe692d3f87bdced02f63158a8fe9679
sha256: 51a8515167f7495b5a8cf19ae372797d92f5b4212b99a941cd74c239f88ad9aa
sha512: 5caf3a761f4fbf0e05823e3db993134157ca69beef537c4c94d831ae4555e4ffb918920d13c84b137ddf76a03e7393ef940fd4e26035684002bbdce2a9c29ef1
ssdeep: 3072:rj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkS7xQr3pwsv1fi:rHgtEWPsL/aTyT9GkSFY3pwss
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Ad., Author: Evan Adam, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Aug 17 07:47:00 2020, Last Saved Time/Date: Mon Aug 17 07:47:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 19, Security: 0

Version Info:

0: [No Data]

OLE.Emotet.38776 also known as:

Elasticmalicious (high confidence)
DrWebExploit.Siggen2.21501
MicroWorld-eScanVB:Trojan.Agent.EVBJ
FireEyeVB:Trojan.Agent.EVBJ
CAT-QuickHealOLE.Emotet.38776
McAfeeW97M/Dropper.gc
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
SymantecTrojan.Gen.2
TrendMicro-HouseCallTrojan.W97M.POWLOAD.TIOIBEMK
AvastScript:SNH-gen [Trj]
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.Agent.EVBJ
ViRobotDOC.Z.Agent.233257
RisingDownloader.Agent/VBA!1.CAB5 (CLASSIC)
Ad-AwareVB:Trojan.Agent.EVBJ
F-SecureMalware.W97M/Agent.6712213
TrendMicroTrojan.W97M.POWLOAD.TIOIBEMK
FortinetVBA/Agent.GC!tr.dldr
SophosTroj/DocDl-AAGA
CyrenW97M/Downldr.IE.gen!Eldorado
AviraW97M/Agent.6712213
ArcabitVB:Trojan.Agent.EVBJ
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
AhnLab-V3Downloader/DOC.Emotet.S1072
ZonerProbably Heur.W97Obfuscated
ESET-NOD32GenScript.JUG
TencentHeur.Macro.Generic.h.5f525bfa
IkarusTrojan-Downloader.VBA.Emotet
GDataGeneric.Trojan.Agent.JKGL5Q
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1065

How to remove OLE.Emotet.38776?

OLE.Emotet.38776 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment