Trojan

TrojanDownloader:O97M/EncDoc.ZZL!MTB information

Malware Removal

The TrojanDownloader:O97M/EncDoc.ZZL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/EncDoc.ZZL!MTB virus can do?

  • The office file contains anomalous features
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine TrojanDownloader:O97M/EncDoc.ZZL!MTB?


File Info:

crc32: CF156805
md5: 06c93387b51aab86d197c83076bd7b68
name: upload_file
sha1: cacc5ffe0c1855c5a005a09ffeddb5b87820e547
sha256: 2cf7a24b0304e8801dafe9b9e060a75e45f354c293fb26d2a414c9e936fe09e7
sha512: 3edfc75dcda6a23d63773f50e5fb4b152d3c82e804ad3afe13f20ba4086dade4c41756c63e1ed2258c546307b76147a8587eef50c9fa143a041448b7b09c7798
ssdeep: 1536:Kk3hOdsylKlgryzc4bNhZFGzE+cL2knAicEjmEJS4OZMoiC8oWaX0z7:Kk3hOdsylKlgryzc4bNhZFGzE+cL2kn/
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Oct 23 11:21:20 2020, Last Saved Time/Date: Fri Oct 23 12:25:38 2020, Security: 0

Version Info:

0: [No Data]

TrojanDownloader:O97M/EncDoc.ZZL!MTB also known as:

DrWebExploit.Siggen2.54800
McAfeeRDN/ZLoader
K7AntiVirusTrojan ( 0056ab8f1 )
K7GWTrojan ( 0056ab8f1 )
KasperskyHEUR:Trojan.Script.Generic
AegisLabTrojan.Script.Generic.4!c
McAfee-GW-EditionRDN/ZLoader
MicrosoftTrojanDownloader:O97M/EncDoc.ZZL!MTB
ZoneAlarmHEUR:Trojan.Script.Generic
ZonerProbably Heur.W97ShellB
FortinetMSExcel/Agent.AG!tr.dldr
Qihoo-360Generic/Trojan.Script.ed4

How to remove TrojanDownloader:O97M/EncDoc.ZZL!MTB?

TrojanDownloader:O97M/EncDoc.ZZL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment