Malware

OLE.Emotet.39191 (file analysis)

Malware Removal

The OLE.Emotet.39191 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OLE.Emotet.39191 virus can do?

  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine OLE.Emotet.39191?


File Info:

crc32: DA61EE40
md5: c10505e78547af025ed36f903c10dba3
name: upload_file
sha1: c0d63b1a9094862a02b1225b7faecd5d229fdd88
sha256: 5d5e964840d2d7f401bae3568724b259b02c4485c211ccc7ec23c0273d11edd1
sha512: 776869512344ce6d2e53b616eee4e4e26b7b5cc93e3d7067a0f32857d761f3b85fe47cdb1c6243f3ff906a12f4c04e1eb574311a6ac3ebdb27de699104371c0b
ssdeep: 1536:BB445TEgrO3jSWAg83tle1ZZ0293QM0eetR2cOupLB5UZ5p+a9K2v9GnJbGrh+CK:B22TWTogk079THcpOu5UZOTyKGfg
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Omnis., Author: Lmo Leclerc, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Sep 23 10:30:00 2020, Last Saved Time/Date: Wed Sep 23 10:30:00 2020, Number of Pages: 1, Number of Words: 2234, Number of Characters: 12736, Security: 0

Version Info:

0: [No Data]

OLE.Emotet.39191 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVBA:Logan.861
FireEyeVBA:Logan.861
CAT-QuickHealOLE.Emotet.39191
McAfeeW97M/Downloader.dbv
K7AntiVirusTrojan ( 0056edf51 )
K7GWTrojan ( 0056edf51 )
InvinceaTroj/DocDl-AAQH
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.EMOTET.TIOIBELH
AvastOther:Malware-gen [Trj]
ClamAVDoc.Downloader.Emotet-9765530-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVBA:Logan.861
RisingMalware.ObfusVBA@ML.97 (VBA)
Ad-AwareVBA:Logan.861
EmsisoftTrojan-Downloader.Macro.Generic.BG (A)
Comodo.UnclassifiedMalware@0
F-SecureMalware.W97M/Agent.5195314
DrWebExploit.Siggen2.42206
TrendMicroTrojan.W97M.EMOTET.TIOIBELH
McAfee-GW-EditionW97M/Downloader.dbv
SophosTroj/DocDl-AAQH
SentinelOneDFI – Malicious OLE
AviraW97M/Agent.5195314
MAXmalware (ai score=57)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ufy
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
ArcabitVBA:Logan.861
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataGeneric.Trojan.Agent.XZB2QL
CynetMalicious (score: 85)
AhnLab-V3Downloader/DOC.Emotet.S1294
ALYacTrojan.Downloader.DOC.Gen
ESET-NOD32VBA/TrojanDownloader.Agent.UFY
TencentHeur.Macro.Generic.f.9c9e592a
IkarusTrojan-Downloader.VBA.Emotet
FortinetVBA/Dloader.MRYV!tr
AVGOther:Malware-gen [Trj]
Qihoo-360virus.office.qexvmc.1090

How to remove OLE.Emotet.39191?

OLE.Emotet.39191 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment