Malware

How to remove “Exploit:O97M/CVE-2017-11882.YF!MTB”?

Malware Removal

The Exploit:O97M/CVE-2017-11882.YF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:O97M/CVE-2017-11882.YF!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

Related domains:

redirector.gvt1.com
r4—sn-4g5ednsy.gvt1.com
update.googleapis.com

How to determine Exploit:O97M/CVE-2017-11882.YF!MTB?


File Info:

crc32: D7DCF86B
md5: 5f5012c25dd2d7c592055f90d8c6e2b8
name: upload_file
sha1: f51f9a2d5598bb12b7e7ce7f537cb393d1ca52d5
sha256: 1282898344e4a24c2c54d4d401c0b5104bb249eee5a3c8bd076a34429089ce26
sha512: 4b1482760d9544e82c2af1e96d9279ee9062be11690122a78c0e00fb10a14aeb60fb609a29a5050cfee5782a6914c8632fa51f414a7880ea74028fe10873ac58
ssdeep: 12288:+Lq8z726774JeYiIDl1r72Z3Iuseb7pv0BHSaAQ3mjka:+57BgewB7+3se321S83s
type: Composite Document File V2 Document, No summary info

Version Info:

0: [No Data]

Exploit:O97M/CVE-2017-11882.YF!MTB also known as:

DrWebExploit.Siggen2.47990
MicroWorld-eScanExploit.CVE-2017-11882.Gen
FireEyeExploit.CVE-2017-11882.Gen
McAfeeExploit-GBR!67B5FBECF3E0
TrendMicroTROJ_FRS.0NA103J620
SymantecTrojan Horse
TrendMicro-HouseCallTROJ_FRS.0NA103J620
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Exploit.MSOffice.Generic
BitDefenderExploit.CVE-2017-11882.Gen
ViRobotDOC.Z.CVE-2017-1188.677888.B
AegisLabHacktool.MSOffice.Generic.3!c
Ad-AwareExploit.CVE-2017-11882.Gen
TACHYONSuspicious/W97.CVE-2017-11882
SophosTroj/DocExp-AB
ComodoMalware@#17euy5r392joa
F-SecureExploit.EXP/W97M.Agent.njyhi
InvinceaTroj/DocExp-AB
McAfee-GW-EditionArtemis!Trojan
EmsisoftExploit.CVE-2017-11882.Gen (B)
AviraEXP/W97M.Agent.njyhi
MicrosoftExploit:O97M/CVE-2017-11882.YF!MTB
ArcabitExploit.CVE-2017-11882.Gen
ZoneAlarmHEUR:Exploit.MSOffice.Generic
GDataExploit.CVE-2017-11882.Gen
CynetMalicious (score: 85)
ALYacExploit.CVE-2017-11882.Gen
MAXmalware (ai score=100)
ESET-NOD32multiple detections
IkarusTrojan-Downloader.Office.Crypt
FortinetMSOffice/CVE_2017_11882.C!exploit
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Exploit.ed7

How to remove Exploit:O97M/CVE-2017-11882.YF!MTB?

Exploit:O97M/CVE-2017-11882.YF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment