Malware

OLE.Emotet.38799 malicious file

Malware Removal

The OLE.Emotet.38799 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OLE.Emotet.38799 virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with suspicious strings

How to determine OLE.Emotet.38799?


File Info:

crc32: 954C772E
md5: 9c2c74cac8f107cd78408b10cac5e180
name: upload_file
sha1: cadac10ef3d0ae5a6199a78464873ae7127a345c
sha256: 2e95bd704e2338cda9beb47c247cdff745c25b1966f04073e4ea60f8b630368f
sha512: f5f8a811025cf0e9feb4fdeaa7460d907d3acc78a2e466b15b66bdab9a8866f48606e12b78d52e9ecdb2edb8269d626e7f6a101e59bb7dfd9c557b8ccfde05ca
ssdeep: 3072:ij6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkefkKvvvU7rwzYm:iHgtEWPsL/aTyT9GkukKv3ErwzYm
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Aut., Author: Valentin Nicolas, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Aug 20 08:53:00 2020, Last Saved Time/Date: Thu Aug 20 08:53:00 2020, Number of Pages: 1, Number of Words: 4, Number of Characters: 23, Security: 0

Version Info:

0: [No Data]

OLE.Emotet.38799 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVBA.Heur2.Amphitryon.1266.Gen
FireEyeVBA.Heur2.Amphitryon.1266.Gen
CAT-QuickHealOLE.Emotet.38799
McAfeeW97M/Downloader.ddv
AegisLabTrojan.MSWord.Generic.4!c
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
InvinceaMal/DocDl-K
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.TIOIBEMN
AvastSNH:Script [Dropper]
ClamAVDoc.Downloader.Emotet-9416473-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVBA.Heur2.Amphitryon.1266.Gen
NANO-AntivirusTrojan.Script.Downloader.htfcpy
ViRobotDOC.Z.Agent.242704
TencentHeur.Macro.Generic.h.bb9d4984
Ad-AwareVBA.Heur2.Amphitryon.1266.Gen
EmsisoftTrojan-Downloader.Macro.Generic.AO (A)
F-SecureMalware.VBA/Dldr.Agent.ageqm
DrWebExploit.Siggen2.25057
TrendMicroTrojan.W97M.POWLOAD.TIOIBEMN
SophosMal/DocDl-K
IkarusTrojan-Downloader.VBA.Emotet
GDataMacro.Trojan-Downloader.Agent.AUK
AviraVBA/Dldr.Agent.ageqm
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ubm
ArcabitVBA.Heur2.Amphitryon.1266.Gen
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
CynetMalicious (score: 85)
AhnLab-V3Downloader/DOC.Emotet.S1285
ALYacTrojan.Downloader.DOC.Gen
MAXmalware (ai score=99)
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UCS
RisingMalware.ObfusVBA@ML.99 (VBA)
FortinetVBA/Agent.GC!tr.dldr
AVGSNH:Script [Dropper]
Qihoo-360virus.office.qexvmc.1065

How to remove OLE.Emotet.38799?

OLE.Emotet.38799 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment