Trojan

About “TrojanDownloader.O97M.Emotet” infection

Malware Removal

The TrojanDownloader.O97M.Emotet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader.O97M.Emotet virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader.O97M.Emotet?


File Info:

crc32: F7F884F5
md5: 5809e1e286cb9445976403fed8323c84
name: upload_file
sha1: 36e82db7c17c8cd8db5f8ce894175578cffa9f2f
sha256: 608640cc09523824170abe5439a993ab6057204ad82c3c3af46ac0ebcf7cf38d
sha512: 80cca52e14ff2af48f760732af5ba0b8b7aa109c5ba1a2b92be9cd019093b331f7fbcbae325b00d6b4628bd370259d03b0dea37f2738de5ff107b2cf855c2450
ssdeep: 3072:cj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkSRVLmgG8MBw9DR2C:cHgtEWPsL/aTyT9Gk+uFw9DRR
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Ea., Author: Th.o Garcia, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Sat Aug 15 00:47:00 2020, Last Saved Time/Date: Sat Aug 15 00:47:00 2020, Number of Pages: 1, Number of Words: 4, Number of Characters: 23, Security: 0

Version Info:

0: [No Data]

TrojanDownloader.O97M.Emotet also known as:

Elasticmalicious (high confidence)
ClamAVDoc.Downloader.Emotet-9349720-0
FireEyeW97m.Downloader.IXO
CAT-QuickHealOLE.Emotet.38763
McAfeeW97M/Downloader.ddv
VIPRETrojan-Downloader.W97M.Agent.jc (v)
AegisLabTrojan.MSOffice.SAgent.4!c
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.EMOTET.TIOIBEKN
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderW97m.Downloader.IXO
ViRobotDOC.Z.Agent.236567.A
MicroWorld-eScanW97m.Downloader.IXO
RisingDownloader.Agent/VBA!1.CA83 (CLASSIC)
Ad-AwareW97m.Downloader.IXO
Comodo.UnclassifiedMalware@0
F-SecureMalware.W97M/Agent.4993111
DrWebExploit.Siggen2.19771
TrendMicroTrojan.W97M.EMOTET.TIOIBEKN
SophosMal/DocDl-K
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.4993111
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ubm
MicrosoftTrojanDownloader:O97M/Emotet!rfn
ArcabitW97m.Downloader.IXO
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataW97m.Downloader.IXO
AhnLab-V3Downloader/MSOffice.Generic
ALYacTrojan.Downloader.DOC.Gen
VBA32TrojanDownloader.O97M.Emotet
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UBM
TencentHeur.Macro.Generic.h.a5418dee
FortinetVBA/Agent.GC!tr.dldr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1075

How to remove TrojanDownloader.O97M.Emotet?

TrojanDownloader.O97M.Emotet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment