Trojan

TrojanDownloader:O97M/Obfuse.FM!MTB removal

Malware Removal

The TrojanDownloader:O97M/Obfuse.FM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/Obfuse.FM!MTB virus can do?

  • The office file has a unconventional code page: ANSI Cyrillic; Cyrillic (Windows)
  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:O97M/Obfuse.FM!MTB?


File Info:

crc32: 2C780A1F
md5: c4dc25fdbdc0b722de6cb190e08757ce
name: upload_file
sha1: d52e95b887badf0081d66965913555a0b59f00e9
sha256: 5e84efe4d51ed6e3de4aca32ec599edaf9fd1a2ff1a45dae5d471a53fd121e3e
sha512: 7fe15ed619e2957ba3563c05c807e673f9927e1a4324c95114aca04dd30e1fc1dfb18a55a3840278b7ef1fe5346b242e6875c2228344302c51c3398c211c9a48
ssdeep: 24576:tGSXr2OvYpyWp9apTVM7m7kP7P7x7BO7U9MnNYR7Z7IxfKy7Whgeu27vlHq7kN8:QS2RpyWpQTHjV
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Author: 1, Template: Normal.dotm, Last Saved By: 1, Revision Number: 13, Name of Creating Application: Microsoft Office Word, Total Editing Time: 21:00, Create Time/Date: Mon Oct 5 16:45:00 2020, Last Saved Time/Date: Tue Oct 6 16:52:00 2020, Number of Pages: 1, Number of Words: 0, Number of Characters: 1, Security: 0

Version Info:

0: [No Data]

TrojanDownloader:O97M/Obfuse.FM!MTB also known as:

MicroWorld-eScanTrojan.Agent.EXLH
FireEyeTrojan.Agent.EXLH
K7AntiVirusTrojan ( 0056edf51 )
K7GWTrojan ( 0056edf51 )
InvinceaTroj/DocDrp-YZ
AvastScript:SNH-gen [Trj]
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.Agent.EXLH
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
Ad-AwareTrojan.Agent.EXLH
EmsisoftTrojan.Agent.EXLH (B)
F-SecureHeuristic.HEUR/Macro.Downloader.MRYX.Gen
McAfee-GW-EditionBehavesLike.OLE2.Downloader.tg
SophosTroj/DocDrp-YZ
SentinelOneDFI – Malicious OLE
AviraW97M/Dldr.Agent.qkznx
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent
MicrosoftTrojanDownloader:O97M/Obfuse.FM!MTB
ArcabitTrojan.Agent.EXLH
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.Agent.EXLH
CynetMalicious (score: 85)
TACHYONSuspicious/W97M.Obfus.Gen.8
ZonerProbably Heur.W97Obfuscated
RisingDownloader.Obfuse!8.105AD (TOPIS:E0:3AFMAjoYl2C)
FortinetVBA/Agent.5215!tr
AVGScript:SNH-gen [Trj]

How to remove TrojanDownloader:O97M/Obfuse.FM!MTB?

TrojanDownloader:O97M/Obfuse.FM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment