Malware

W97M.Downloader.35060 (file analysis)

Malware Removal

The W97M.Downloader.35060 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W97M.Downloader.35060 virus can do?

  • The office file contains a macro
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

How to determine W97M.Downloader.35060?


File Info:

crc32: 9FACA580
md5: d6cf9c092b7f09e43f6e3083b9124129
name: upload_file
sha1: c2edcb60886e83967799b10141a739a83895afd1
sha256: 9688cd9ff2c76566a55ae026e7b78e748565edf682ec5cbbdf9c2389a12a3ef9
sha512: 1c54d1c7dcc26503b40cc2f371a3cb90654be140dd579b6fd73e295c56cfdd3fde797554cb12c604c5a2a5d830343e25744354800646aa00b916d167867c54f3
ssdeep: 6144:3lXe/kJVx/3WDJ6sv6PTNONyqtNG2DyrXcfVBPxXtrkADdPm2M6mklG9/+RLv/6:3wMzxsfNNywNGCV/4AJPlGZ+RL4Ngj9
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: oplup, Template: Normal.dotm, Last Saved By: HP, Revision Number: 4, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Oct 14 10:14:00 2020, Last Saved Time/Date: Wed Oct 14 10:23:00 2020, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0

Version Info:

0: [No Data]

W97M.Downloader.35060 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44081748
CAT-QuickHealW97M.Downloader.35060
ALYacTrojan.GenericKD.44081748
SangforMalware
K7AntiVirusTrojan ( 0056edf51 )
K7GWTrojan ( 0056edf51 )
TrendMicroTROJ_FRS.0NA103JF20
CyrenW97M/Agent.gen
SymantecW97M.Downloader
TrendMicro-HouseCallTROJ_FRS.0NA103JF20
KasperskyHEUR:Trojan-Downloader.Script.Generic
BitDefenderTrojan.GenericKD.44081748
NANO-AntivirusTrojan.Script.Agent.dmmmmt
ViRobotDOC.Z.Agent.524288.R
AegisLabTrojan.Script.Generic.a!c
RisingDownloader.Agent!1.C02D (CLASSIC)
Ad-AwareTrojan.GenericKD.44081748
EmsisoftTrojan.GenericKD.44081748 (B)
F-SecureMalware.VBA/Dldr.Agent.cxxdv
DrWebExploit.Siggen2.49681
McAfee-GW-EditionBehavesLike.OLE2.Downloader.hb
FireEyeTrojan.GenericKD.44081748
IkarusTrojan-Downloader.VBA.Agent
AviraVBA/Dldr.Agent.cxxdv
MAXmalware (ai score=99)
MicrosoftTrojan:Win32/Ymacco.AA96
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
GDataTrojan.GenericKD.44081748
CynetMalicious (score: 85)
McAfeeW97M/Downloader.dk
TACHYONSuspicious/W97M.Obfus.Gen.8
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.DWR
TencentHeur.MSWord.Downloader.d
SentinelOneDFI – Malicious OLE
FortinetVBA/Agent.XXV!tr.dldr
Qihoo-360virus.office.qexvmc.1085

How to remove W97M.Downloader.35060?

W97M.Downloader.35060 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment