Malware

Exploit:O97M/CVE-2017-0199!MTB removal guide

Malware Removal

The Exploit:O97M/CVE-2017-0199!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:O97M/CVE-2017-0199!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Exploit:O97M/CVE-2017-0199!MTB?


File Info:

crc32: 8B897F4D
md5: 7705daee7fe9d3277a137e0829c75073
name: upload_file
sha1: f790c2a8fbad2840c183c8d6f5c1eeb224b5cb91
sha256: 2e15de2fa5d58fb77fa17fe850cac04411b053d5d361a42f20d771252c44e7a7
sha512: 9872b0423c1c45c44d2b1ba08572ba6480c4e0c872e0b2713d51c3710d0b25c69add5a1d54123b0d0ebdd1ebdfab0576fb413ea1d79a39011c2d2041a939d6a4
ssdeep: 3072:/Njma2B1ta3NeB/WtUqFskAffE1L/4xQeJ2Bb11BBlBML/oEG9mI6lLUiwMF5bT5:ElB3sA9WMEZ4xQeJ2B/EbemfU3MFF9
type: Composite Document File V2 Document, No summary info

Version Info:

0: [No Data]

Exploit:O97M/CVE-2017-0199!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.43985540
FireEyeTrojan.GenericKD.43985540
McAfeeRDN/Generic Exploit
SymantecTrojan.Gen.MBT
KasperskyHEUR:Exploit.MSOffice.CVE-2017-0199.a
BitDefenderTrojan.GenericKD.43985540
ViRobotDOC.Z.CVE-2017-0199.175104.M
Ad-AwareTrojan.GenericKD.43985540
EmsisoftTrojan.GenericKD.43985540 (B)
F-SecureExploit.EXP/CVE-2017-0199.javlp
McAfee-GW-EditionRDN/Generic Exploit
IkarusExploit.CVE-2017-0199
AviraEXP/CVE-2017-0199.javlp
MicrosoftExploit:O97M/CVE-2017-0199!MTB
ArcabitTrojan.Generic.D29F2A84
ZoneAlarmHEUR:Exploit.MSOffice.CVE-2017-0199.a
GDataTrojan.GenericKD.43985540
CynetMalicious (score: 85)
ALYacExploit.CVE-2017-0199
TACHYONSuspicious/W97.CVE-2017-0199
ESET-NOD32a variant of Generik.NUMFRUQ
FortinetMSOffice/CVE_2017_0199.A!exploit
Qihoo-360Generic/Trojan.Exploit.769

How to remove Exploit:O97M/CVE-2017-0199!MTB?

Exploit:O97M/CVE-2017-0199!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment