Trojan

TrojanDownloader:O97M/Obfuse.JM!MTB information

Malware Removal

The TrojanDownloader:O97M/Obfuse.JM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/Obfuse.JM!MTB virus can do?

  • The office file contains 4 macros
  • The office file contains a macro with auto execution
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine TrojanDownloader:O97M/Obfuse.JM!MTB?


File Info:

crc32: 2349B51F
md5: 7aaaa63832e4eb35660a3fe70a1ea5d8
name: upload_file
sha1: 0972a684a2cf295531590733b23b6a89613dc3e7
sha256: f10ad972a5c700271115513d98738334503fc5e809cc75512f4afb845629d84d
sha512: bbf8ce34e0b3187915ee66a29fb06ab9c302cd7b4c89ef933c94c31716f3aaba0be3ff3d0cc229420643193ece86d05e9b9ce54b954e1d478aca219024bcd378
ssdeep: 3072:QfZBHqq2Q11qJ8aB7UufWwMEPZdZQdBTUH12kBHND:czHp2Q1kJ8aB7z+LERdZQd2Xv
type: Microsoft Word 2007+

Version Info:

0: [No Data]

TrojanDownloader:O97M/Obfuse.JM!MTB also known as:

Elasticmalicious (high confidence)
BitDefenderTrojan.DOC.Agent.AQI
ArcabitHEUR.VBA.CG.1
CyrenPP97M/Agent.KC.gen!Eldorado
SymantecISB.Downloader!gen428
ESET-NOD32VBA/TrojanDownloader.Agent.UPC
TrendMicro-HouseCallTrojan.W97M.POWLOAD.THJOGBO
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
AlibabaTrojanDownloader:VBA/Obfuscation.A
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
MicroWorld-eScanTrojan.DOC.Agent.AQI
EmsisoftTrojan.DOC.Agent.AQI (B)
TrendMicroTrojan.W97M.POWLOAD.THJOGBO
McAfee-GW-EditionBehavesLike.Downloader.cc
FireEyeTrojan.DOC.Agent.AQI
SentinelOneDFI – Malicious OPENXML
MAXmalware (ai score=89)
MicrosoftTrojanDownloader:O97M/Obfuse.JM!MTB
ZoneAlarmUDS:DangerousObject.Multi.Generic
ZonerProbably Heur.W97Obfuscated
IkarusTrojan-Downloader.VBA.Agent
Qihoo-360virus.office.obfuscated.1

How to remove TrojanDownloader:O97M/Obfuse.JM!MTB?

TrojanDownloader:O97M/Obfuse.JM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment