Malware

W97M.Emotet.38758 information

Malware Removal

The W97M.Emotet.38758 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W97M.Emotet.38758 virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine W97M.Emotet.38758?


File Info:

crc32: D17E2D69
md5: 480b10c2ca56d4bd2c6c2adc99921d8d
name: upload_file
sha1: 4b05917c5be18a29715acca7381017ad93da60e4
sha256: c9d13f60323ba6bfa94d8444d9f72f4301f6a5a9eb61827dfbb7d059d7c430b4
sha512: 54b2cfde333924c3e59b75bb79d387a053e6fcb586af7af9cdac984f74a2c488c9570c5181e63d6f517d8539f011b767bab4f6385c7f09a7d8ea600525574495
ssdeep: 3072:Mj6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGk1E5zVT3wYzRO:MHgtEWPsL/aTyT9Gk1E5pLwYzRO
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Ducimus., Author: Lua Barre, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Tue Aug 11 22:52:00 2020, Last Saved Time/Date: Tue Aug 11 22:52:00 2020, Number of Pages: 2, Number of Words: 5, Number of Characters: 29, Security: 0

Version Info:

0: [No Data]

W97M.Emotet.38758 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanW97M.Agent.MG
FireEyeW97M.Agent.MG
CAT-QuickHealW97M.Emotet.38758
McAfeeW97M/Dropper.gc
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.TIOIBEMH
AvastScript:SNH-gen [Trj]
ClamAVDoc.Malware.Sagent-9275219-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderW97M.Agent.MG
ViRobotDOC.Z.Agent.230209.A
AegisLabTrojan.MSOffice.SAgent.4!c
RisingMalware.ObfusVBA@ML.99 (VBA)
Ad-AwareW97M.Agent.MG
ComodoTrojWare.Win32.Agent.nrffq@0
F-SecureMalware.VBA/Dldr.Agent.fsnca
DrWebExploit.Siggen2.17020
TrendMicroTrojan.W97M.POWLOAD.TIOIBEMH
FortinetVBA/Agent.BIP!tr.dldr
SophosMal/DocDl-L
CyrenW97M/Downldr.IE.gen!Eldorado
AviraVBA/Dldr.Agent.fsnca
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.uay
ArcabitW97M.Agent.MG
MicrosoftTrojanDownloader:O97M/Emotet!MSR
CynetMalicious (score: 85)
AhnLab-V3Downloader/DOC.Emotet.S1072
ALYacTrojan.Downloader.DOC.Gen
TACHYONSuspicious/W97M.Obfus.Gen.1
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UAY
TencentHeur.Macro.Generic.f.166221cf
IkarusTrojan-Downloader.VBA.Emotet
GDataW97M.Agent.MG
AVGScript:SNH-gen [Trj]
Qihoo-360Generic/Trojan.3b4

How to remove W97M.Emotet.38758?

W97M.Emotet.38758 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment