Trojan

Trojan.Dropper.X97M (file analysis)

Malware Removal

The Trojan.Dropper.X97M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dropper.X97M virus can do?

  • The office file contains 9 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine Trojan.Dropper.X97M?


File Info:

crc32: FDD30A93
md5: 02ccb973397cf858c511bb7fc769c00b
name: upload_file
sha1: c682a99b59ae8c2416ff1d8501250c17fa8ab583
sha256: cf1a238f88b3642f97d0d4dfdeacdcbaccb2ab9481b2ecffa7921d0bfbcc97e2
sha512: 38d88498b2b2299af4e6ec8c78fbc56f14c49d4fb1d39dc93964cbe1bd49abe4e43818ba03ded331ad873047eb1199d2cd910a7a9c939720fb2540584c0f3811
ssdeep: 12288:Ro2aJZEy3/AdZOdvfXeGlbU6dRE1eK/KaV+JvT7yYVsi6UqttsQfE4b6ItaQXWn:hajEa/AsfXeGlbldRpKCn77PnFD6Knz
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jun 22 11:41:03 2020, Last Saved Time/Date: Thu Aug 20 11:18:49 2020, Security: 0

Version Info:

0: [No Data]

Trojan.Dropper.X97M also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.18684
MicroWorld-eScanTrojan.GenericKD.43699382
FireEyeTrojan.GenericKD.43699382
CAT-QuickHealX97M.Downloader.38800
McAfeeW97M/Downloader.dds
SangforMalware
TrendMicroTROJ_FRS.0NA103HK20
BitDefenderThetaGen:NN.ZedlaF.34216.ty5@aSY3W2ci
CyrenPNG/Trojan.USCY-8
SymantecW97M.Downloader
TrendMicro-HouseCallTROJ_FRS.0NA103HK20
AvastOther:Malware-gen [Trj]
ClamAVWin.Dropper.Hideproc-6663113-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.43699382
NANO-AntivirusTrojan.Win32.Redcap.hsqoli
AegisLabTrojan.Script.Generic.4!c
TencentWin32.Trojan.Generic.Fii
Ad-AwareTrojan.GenericKD.43699382
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/Macro.Downloader.MRUZ.Gen
InvinceaTroj/DocDl-AAGO
SophosTroj/DocDl-AAGO
SentinelOneDFI – Malicious OLE
AviraHEUR/Macro.Downloader.MRUZ.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.Generic
MicrosoftTrojanDropper:O97M/GraceWire.ARK!MTB
ArcabitTrojan.Generic.D29ACCB6
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.43699382
CynetMalicious (score: 85)
VBA32Trojan.Downloader
ALYacTrojan.Dropper.X97M
TACHYONSuspicious/W97.NS.Gen
ZonerProbably Heur.W97Call
ESET-NOD32GenScript.JVI
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
IkarusTrojan.Office.Doc
FortinetW32/Dropper.GIF!tr
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Script.ed4

How to remove Trojan.Dropper.X97M?

Trojan.Dropper.X97M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment