Trojan

TrojanDownloader:O97M/EnCDoc.RQ!MTB malicious file

Malware Removal

The TrojanDownloader:O97M/EnCDoc.RQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/EnCDoc.RQ!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine TrojanDownloader:O97M/EnCDoc.RQ!MTB?


File Info:

crc32: 49411546
md5: 7c94d5ab21646cbd6d053509de55a80e
name: 7C94D5AB21646CBD6D053509DE55A80E.mlw
sha1: 25c5a3b572ee7837061838cacccdc5fa280f8648
sha256: 5b0bf4defd88befa231c4ebe655ae860b180baa8e0331cd6c570d31f6751b9bd
sha512: de12a70d04aa043d1c8510edd18c907175ed0c8d936b3f47766c6b767eb31fa83a2ef75bc287de2dcf48e7403c611b4cb10379bd79366aa5f0b1d23c0d47520f
ssdeep: 12288:d1ghp5DubQKErdxA+zM5miTrqZj1kENwNmhxOMNU:K1rv05T+ZjHNwKOM
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:O97M/EnCDoc.RQ!MTB also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Qbot.DD
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan-Banker.Win32.Cridex
BitDefenderTrojan.GenericKD.37628655
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojanDownloader:O97M/EnCDoc.RQ!MTB
ZoneAlarmUDS:DangerousObject.Multi.Generic
McAfeeRDN/Qakbot
TrendMicro-HouseCallTrojanSpy.Win32.QAKBOT.YXBIWZ
FortinetW32/Malicious_Behavior.VEX
AVGFileRepMalware
Paloaltogeneric.ml

How to remove TrojanDownloader:O97M/EnCDoc.RQ!MTB?

TrojanDownloader:O97M/EnCDoc.RQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment