Categories: Trojan

TrojanDownloader:O97M/Obfuse.BPK!MTB information

The TrojanDownloader:O97M/Obfuse.BPK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/Obfuse.BPK!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:O97M/Obfuse.BPK!MTB?


File Info:

crc32: AEE52B72md5: 942b5d3731110e95c84e8fb7c4e31bf3name: upload_filesha1: 0ae08dc9f7ddd5bdd273c977c06b842835b890c5sha256: 8951edf18c219c38e0458b432e2ad7acb408dd78347d4be3bbbcf30c740d9d74sha512: 4b23089e446258d07fdff208868d43042c6656f7dae694458af50246db111b074941eab3eb0ec2e5eb2bff9d841f9732f8ed4f2c8c8b6b640196219ac065c319ssdeep: 192:0mn87BGaI/tSpGhUp3vFWzYp+B7kS580cFqgQHTIUXhWBS0ZApg1nnHXcvTBFoP:036tlhuvFgFnzGBn3clFo39Dtype: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: product presentation, Last Saved By: Master Mana, Revision Number: 3, Name of Creating Application: Microsoft Office PowerPoint, Total Editing Time: 05:52, Create Time/Date: Wed Oct 14 07:08:37 2020, Last Saved Time/Date: Wed Oct 14 07:14:29 2020, Number of Words: 0

Version Info:

0: [No Data]

TrojanDownloader:O97M/Obfuse.BPK!MTB also known as:

Elastic malicious (high confidence)
AegisLab Trojan.Script.Generic.a!c
Arcabit Trojan.Generic.D212929D
Cyren PP97M/Downldr.NU.gen!Eldorado
Symantec Trojan.Gen.NPE
TrendMicro-HouseCall Trojan.P97M.POWLOAD.AI
Avast VBS:Obfuscated-gen [Trj]
Cynet Malicious (score: 85)
Kaspersky HEUR:Trojan-Downloader.Script.Generic
BitDefender Trojan.GenericKD.34771613
MicroWorld-eScan Trojan.GenericKD.34771613
Rising Malware.ObfusVBA@ML.99 (VBA)
Ad-Aware Trojan.GenericKD.34771613
Emsisoft Trojan.GenericKD.34771613 (B)
F-Secure Heuristic.HEUR/Macro.Downloader.MRKI.Gen
TrendMicro Trojan.P97M.POWLOAD.AI
McAfee-GW-Edition BehavesLike.OLE2.Downloader.kx
FireEye Trojan.GenericKD.34771613
Ikarus Win32.Outbreak
Avira HEUR/Macro.Downloader.MRKI.Gen
MAX malware (ai score=99)
Antiy-AVL Trojan[Downloader]/MSOffice.Agent.ubw
Microsoft TrojanDownloader:O97M/Obfuse.BPK!MTB
ViRobot PPT.Z.Agent.70656.B
ZoneAlarm HEUR:Trojan-Downloader.Script.Generic
GData Generic.Trojan.Agent.UZYKL0
ALYac Trojan.GenericKD.34772399
Zoner Probably Heur.W97Obfuscated
ESET-NOD32 a variant of VBA/TrojanDownloader.Agent.UNQ
Tencent Win32.Trojan-downloader.Agent.Hqvb
SentinelOne DFI – Suspicious OLE
Fortinet VBA/Agent.MRKI!tr
AVG VBS:Obfuscated-gen [Trj]
Qihoo-360 Generic/Trojan.Downloader.251

How to remove TrojanDownloader:O97M/Obfuse.BPK!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4222225806 malicious file

The Malware.AI.4222225806 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.1862100968 removal guide

The Malware.AI.1862100968 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Win32:VB-OLS [Trj] removal

The Win32:VB-OLS [Trj] is considered dangerous by lots of security experts. When this infection is…

2 hours ago

How to remove “Trojan:Win32/Smokeloader.CCDO!MTB”?

The Trojan:Win32/Smokeloader.CCDO!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “TrojanDownloader:MSIL/RedLineStealer.KL!MTB”?

The TrojanDownloader:MSIL/RedLineStealer.KL!MTB is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

How to remove “Malware.AI.4139232050”?

The Malware.AI.4139232050 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago