Malware

What is “W97M.Emotet.38696”?

Malware Removal

The W97M.Emotet.38696 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W97M.Emotet.38696 virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine W97M.Emotet.38696?


File Info:

crc32: EC166F3F
md5: d9aba63ea690cf2d9f28e6134026eb82
name: upload_file
sha1: fd6e87af8fa7ffe0613484db6acb0bf7e44b21dd
sha256: c5c24fefed04facf5e5f02de5b7f843fee9594d2f5f356af9dd46a9075e8ed13
sha512: 4f6a79c2d27bb18aaf22795951e97cebb97a85b950badff897c466a49ea72331ecd61fab8cdcc2daf6d63194f84e6d8d5116ff6eb90a5fef00868cbb486281e0
ssdeep: 3072:NMj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkN4Oqi8Dwws9CR5:KHgtEWPsL/aTyT9GkN4Oqi5wsoR5
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Dicta., Author: Quentin Fernandez, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Mon Aug 10 23:42:00 2020, Last Saved Time/Date: Mon Aug 10 23:42:00 2020, Number of Pages: 1, Number of Words: 3, Number of Characters: 23, Security: 0

Version Info:

0: [No Data]

W97M.Emotet.38696 also known as:

Elasticmalicious (high confidence)
DrWebExploit.Siggen2.16762
FireEyeVB:Trojan.VBA.Agent.BGI
CAT-QuickHealW97M.Emotet.38696
McAfeeW97M/Dropper.gc
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecW97M.Downloader
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB:Trojan.VBA.Agent.BGI
AegisLabTrojan.MSOffice.SAgent.4!c
MicroWorld-eScanVB:Trojan.VBA.Agent.BGI
RisingMalware.ObfusVBA@ML.99 (VBA)
Ad-AwareVB:Trojan.VBA.Agent.BGI
F-SecureMalware.W97M/Agent.5505611
TrendMicroPossible_SMPOWLOADBB4
FortinetVBA/Agent.BGA!tr.dldr
SophosMal/DocDl-L
IkarusTrojan-Downloader.VBA.Emotet
AviraW97M/Agent.5505611
MAXmalware (ai score=99)
ArcabitVB:Trojan.VBA.Agent.BGI
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
MicrosoftTrojanDownloader:O97M/Emotet.CSK!MTB
AhnLab-V3Downloader/DOC.Emotet.S1072
ALYacVB:Trojan.VBA.Agent.BGI
TACHYONSuspicious/W97M.Obfus.Gen.1
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UAY
TencentHeur.Macro.Generic.f.6c5dbbc2
GDataVB:Trojan.VBA.Agent.BGI
AVGScript:SNH-gen [Trj]
Qihoo-360Generic/Trojan.3b4

How to remove W97M.Emotet.38696?

W97M.Emotet.38696 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment