Trojan

How to remove “TrojanDownloader:O97M/EncDoc.MFO!MTB”?

Malware Removal

The TrojanDownloader:O97M/EncDoc.MFO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/EncDoc.MFO!MTB virus can do?

  • The office file contains a macro
  • The office file contains a macro with auto execution
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:O97M/EncDoc.MFO!MTB?


File Info:

crc32: 174E00FB
md5: c6d010d13e2f82f180b7f3cfdbd1dde0
name: upload_file
sha1: 8eaedfcedd5861f63243dc4d23df418fa3973137
sha256: c12ce1a73f6ab3029d1286de66751e079068e64bfc56f0652c8e19dd8c45e350
sha512: 91c43e72d6f64c19615b11d883c2e126d60c750f3eea6a20fbd328903b8ad8fc4c461b5a32d72be4539458a1df32671003bfbc16dacb67939f507d94de513e4a
ssdeep: 6144:824sumCmhlOaOJtVyYq1zLmiSB9BS+uJnFPwB5dsDyk:8rsumCmTOa2tVB06Bj8++nFPE7k
type: Microsoft Excel 2007+

Version Info:

0: [No Data]

TrojanDownloader:O97M/EncDoc.MFO!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34387941
ALYacTrojan.Downloader.VBA.gen
AegisLabTrojan.MSWord.Generic.4!c
SangforMalware
BitDefenderTrojan.GenericKD.34387941
CyrenXLSM/Obfuse.A.gen!Camelot
SymantecW97M.Downloader
ESET-NOD32a variant of Generik.FTREZNO
AvastSNH:Script [Dropper]
KasperskyHEUR:Trojan-Downloader.MSOffice.SLoad.gen
AlibabaTrojanDownloader:VBA/Maldoc.ali1000107
TencentHeur.Macro.Generic.h.b7a0bb3b
Ad-AwareTrojan.GenericKD.34387941
FireEyeTrojan.GenericKD.34387941
IkarusTrojan-Downloader.Office.Doc
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.ftr
MicrosoftTrojanDownloader:O97M/EncDoc.MFO!MTB
ArcabitTrojan.Generic.D20CB7E5
ViRobotXLS.Z.Agent.229229
ZoneAlarmHEUR:Trojan-Downloader.MSOffice.SLoad.gen
GDataTrojan.GenericKD.34387941
McAfeeW97M/Downloader.dfa
TACHYONSuspicious/XOX.Downloader.Gen
ZonerProbably Heur.W97Obfuscated
RisingDownloader.Agent/VBA!1.CA14 (CLASSIC)
SentinelOneDFI – Suspicious OPENXML
FortinetVBA/TrojanDownloader.TWJ!tr
AVGSNH:Script [Dropper]
Qihoo-360Generic/Trojan.Downloader.3f4

How to remove TrojanDownloader:O97M/EncDoc.MFO!MTB?

TrojanDownloader:O97M/EncDoc.MFO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment