Malware

Exploit.RTF.CVE-2017-11882 (file analysis)

Malware Removal

The Exploit.RTF.CVE-2017-11882 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.RTF.CVE-2017-11882 virus can do?

  • A potential decoy document was displayed to the user
  • Creates a hidden or system file

How to determine Exploit.RTF.CVE-2017-11882?


File Info:

crc32: C18C51CE
md5: bde54ffe02050054a8017ec6dbbe992a
name: upload_file
sha1: 11ae60eb159162e0721852d96f08e263aa58bf37
sha256: 4934d81f595dc3c1e10eb3b938a1d4f3244c60c083e2fbe5aa2b61d559d01d79
sha512: 934c435eca47698ab6e9ecaa096eb585ed8cc991684af4dee345eec6864970879746984c24b09669bc07637f659bafb3f92bb927992da7711541efb9146ea1b9
ssdeep: 192:acmfVl7jln2daM3Htqhjr/TqBGfNNQ8CdV3jzajh7egrfZlBSjGDRUvm:rmtlHlnua4qp7NN2V3jzajvr4aDRUe
type: Rich Text Format data, unknown version

Version Info:

0: [No Data]

Exploit.RTF.CVE-2017-11882 also known as:

MicroWorld-eScanTrojan.GenericKD.44151020
FireEyeTrojan.GenericKD.44151020
CAT-QuickHealExp.RTF.Obfus.Gen
ALYacTrojan.GenericKD.44151020
CyrenRTF/CVE-2017-11882.N.gen!Camelot
SymantecExp.CVE-2017-11882!g2
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Exploit.RTF.CVE-2017-11882.gen
BitDefenderTrojan.GenericKD.44151020
NANO-AntivirusExploit.Rtf.Heuristic-rtf.dinbqn
TencentWin32.Exploit.Rtf.Pkqv
Ad-AwareTrojan.GenericKD.44151020
DrWebExploit.Siggen2.54677
McAfee-GW-EditionExploit-GCO!BDE54FFE0205
IkarusExploit.CVE-2017-11882
AviraW97M/Abnormal.wolua
MicrosoftExploit:O97M/CVE-2017-11882.JR!MTB
ArcabitTrojan.Generic.D2A1B0EC
AegisLabTrojan.MSOffice.ObfsStrm.4!c
ZoneAlarmHEUR:Exploit.RTF.CVE-2017-11882.gen
GDataTrojan.GenericKD.44151020
AhnLab-V3RTF/Malform-A.Gen
McAfeeExploit-GCO!BDE54FFE0205
ZonerProbably Heur.RTFBadVersion
ESET-NOD32a variant of DOC/Abnormal.B
MAXmalware (ai score=99)
FortinetRTF/CVE_2017_11882.C!exploit
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Exploit.263

How to remove Exploit.RTF.CVE-2017-11882?

Exploit.RTF.CVE-2017-11882 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment