Malware

Should I remove “X97M.Downloader.38800”?

Malware Removal

The X97M.Downloader.38800 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What X97M.Downloader.38800 virus can do?

  • The office file contains 9 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

How to determine X97M.Downloader.38800?


File Info:

crc32: 07A8653A
md5: 95616fb41158c0252932c1e2bcdd4ac9
name: upload_file
sha1: ff655e9a16e29889e8df74fd1727c61c788f1900
sha256: 30ccde0f021b40c8c8ff93ce58272fb6cf87489f2c74fbc93c120eb1017030fa
sha512: 44d26d5d7efe82da29ded1b0d1d4f5a6cd92c5fe6662b86a2ef880288a61cbb7a79857811161fad846ccf8acc5e376863bb2f3c416841a37c37a84b588afd65f
ssdeep: 24576:lajEa/AsfXeGlbldRpKCn77v8ayV+AaoOK6zq:UbDX/xlzpnXzRA8m
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jun 22 11:41:03 2020, Last Saved Time/Date: Thu Aug 20 11:19:27 2020, Security: 0

Version Info:

0: [No Data]

X97M.Downloader.38800 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34395160
FireEyeTrojan.GenericKD.34395160
CAT-QuickHealX97M.Downloader.38800
McAfeeW97M/Downloader.dds
SangforMalware
TrendMicroTROJ_FRS.0NA103HK20
CyrenPNG/Trojan.USCY-8
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_FRS.0NA103HK20
ClamAVWin.Dropper.Hideproc-6663113-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.34395160
NANO-AntivirusTrojan.Win32.Redcap.hsqoli
ViRobotDOC.Z.Agent.1019804.B
AegisLabTrojan.Script.Generic.4!c
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
Ad-AwareTrojan.GenericKD.34395160
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/Macro.Downloader.MRUZ.Gen
DrWebTrojan.DownLoader34.18684
InvinceaTroj/DocDl-AAGO
SophosTroj/DocDl-AAGO
IkarusTrojan.Office.Doc
AviraHEUR/Macro.Downloader.MRUZ.Gen
Antiy-AVLTrojan/Generic.Generic
MicrosoftTrojanDropper:O97M/GraceWire.ARJ!MTB
ArcabitTrojan.Generic.D20CD418
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.34395160
CynetMalicious (score: 85)
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.34395160
TACHYONSuspicious/W97.NS.Gen
ZonerProbably Heur.W97Call
ESET-NOD32GenScript.JVI
TencentWin32.Trojan.Generic.Hsrx
SentinelOneDFI – Malicious OLE
FortinetW32/Dropper.GIF!tr
BitDefenderThetaGen:NN.ZedlaF.34216.ty5@aSY3W2ci
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Script.ed4

How to remove X97M.Downloader.38800?

X97M.Downloader.38800 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment