Malware

About “OLE.Emotet.38799” infection

Malware Removal

The OLE.Emotet.38799 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OLE.Emotet.38799 virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine OLE.Emotet.38799?


File Info:

crc32: 0173D690
md5: cc482f23fbe05aae17f61ae76d675c35
name: upload_file
sha1: d6d08341e6e5046fdd789de8828082e18e07be11
sha256: 568471d2d31e15f9b46076ae0167cdda7da49957b7cb120d330a0e450bc2c7f3
sha512: f6c462e3a210080493069eb4f410ef0bd3d0ae2a365c60f1f172cab3d00fa34cedd4ba38e852d46148fb88a20b3866498039d53ac3f88ace3d1e6c3b5fda818e
ssdeep: 3072:aj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGk/BAQUt41Zhwzu:aHgtEWPsL/aTyT9GkyQUtEZhwzu
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Sapiente., Author: Romain Roux, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Aug 20 08:44:00 2020, Last Saved Time/Date: Thu Aug 20 08:44:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 19, Security: 0

Version Info:

0: [No Data]

OLE.Emotet.38799 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVBA.Heur2.Amphitryon.1266.Gen
FireEyeVBA.Heur2.Amphitryon.1266.Gen
CAT-QuickHealOLE.Emotet.38799
McAfeeW97M/Downloader.ddv
AegisLabTrojan.MSOffice.SAgent.4!c
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
InvinceaMal/DocDl-K
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
ESET-NOD32VBA/TrojanDownloader.Agent.UCS
TrendMicro-HouseCallTrojan.W97M.POWLOAD.TIOIBEMN
AvastSNH:Script [Dropper]
ClamAVDoc.Downloader.Emotet-9448058-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVBA.Heur2.Amphitryon.1266.Gen
NANO-AntivirusTrojan.Script.Downloader.htfcpy
ViRobotDOC.Z.Agent.242407
TencentHeur.Macro.Generic.h.c3e2df35
Ad-AwareVBA.Heur2.Amphitryon.1266.Gen
SophosMal/DocDl-K
Comodo.UnclassifiedMalware@0
F-SecureMalware.W97M/Agent.2957911
DrWebExploit.Siggen2.25162
TrendMicroTrojan.W97M.POWLOAD.TIOIBEMN
EmsisoftTrojan-Downloader.Macro.Generic.AO (A)
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.2957911
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.lgm
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ArcabitVBA.Heur2.Amphitryon.1266.Gen
AhnLab-V3Downloader/DOC.Emotet.S1279
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.AUK
CynetMalicious (score: 85)
ALYacTrojan.Downloader.DOC.Gen
ZonerProbably Heur.W97Obfuscated
RisingMalware.ObfusVBA@ML.99 (VBA)
YandexTrojan.MacroDown.Gen.TN
FortinetVBA/Agent.GC!tr.dldr
AVGSNH:Script [Dropper]
Qihoo-360virus.office.qexvmc.1080

How to remove OLE.Emotet.38799?

OLE.Emotet.38799 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment