Malware

Exploit:O97M/CVE-2017-11882.YD!MTB removal tips

Malware Removal

The Exploit:O97M/CVE-2017-11882.YD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:O97M/CVE-2017-11882.YD!MTB virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Exploit:O97M/CVE-2017-11882.YD!MTB?


File Info:

crc32: D104A693
md5: 8eb1e5c89fb741c40412e39b5dc17be7
name: upload_file
sha1: 2d94a83e3c211f07bf87f6cf517e2b540ac518ab
sha256: 27e018943c5d42bab6d4370b9d4ca2cc662b94b615414517c709c2b7e0e2888d
sha512: dee538a7ec6c23df9b834b0a3a1fd8c46449965ff7db48aeaac9ad072ebd9fff917a0fe5b7734d8a0c730a2f04a84e212b67e3900b7acbde49016198cc4b6e84
ssdeep: 6144:iphkn+zzvIPNsm+tQ1cuoozMxjAhhbR9Ru5kAAk7:gkKzOZQ7xc/99RAAk7
type: Composite Document File V2 Document, No summary info

Version Info:

0: [No Data]

Exploit:O97M/CVE-2017-11882.YD!MTB also known as:

MicroWorld-eScanExploit.CVE-2017-11882.Gen
FireEyeExploit.CVE-2017-11882.Gen
McAfeeExploit-GBR!6BC45F1C93C8
SymantecTrojan.Gen.NPE
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Exploit.MSOffice.Generic
BitDefenderExploit.CVE-2017-11882.Gen
ViRobotDOC.Z.CVE-2017-1188.239104
Ad-AwareExploit.CVE-2017-11882.Gen
SophosExp/20180802-B
DrWebExploit.Siggen2.54672
InvinceaExp/20180802-B
McAfee-GW-EditionArtemis!Trojan
EmsisoftExploit.CVE-2017-11882.Gen (B)
IkarusExploit.CVE-2017-11882
MAXmalware (ai score=99)
MicrosoftExploit:O97M/CVE-2017-11882.YD!MTB
ZoneAlarmHEUR:Exploit.MSOffice.Generic
GDataExploit.CVE-2017-11882.Gen
ALYacExploit.CVE-2017-11882.Gen
TACHYONSuspicious/W97.CVE-2017-11882
ESET-NOD32probably a variant of Win32/Exploit.CVE-2017-11882.C
TencentOffice.Exploit.Generic.Efbd
FortinetMSOffice/CVE_2017_11882.C!exploit
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Exploit.ed7

How to remove Exploit:O97M/CVE-2017-11882.YD!MTB?

Exploit:O97M/CVE-2017-11882.YD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment