Trojan

TrojanDownloader:O97M/Obfuse.PM!MTB information

Malware Removal

The TrojanDownloader:O97M/Obfuse.PM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/Obfuse.PM!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine TrojanDownloader:O97M/Obfuse.PM!MTB?


File Info:

crc32: AB771618
md5: 48eab7b9a8b212f291e5a43e9a65d3e1
name: upload_file
sha1: 379deed8a3d207e930fc3afbf205aee17c19076a
sha256: 316b9d8008691eff15ff130c72920a8406718a1350fd39bb401ed3d23dd881f3
sha512: 1afd92a5eeb9616c02d02b9e6b72fa5eb6b93d0f3a8a21c519765f866e30a5031fb105bf06ec985d56124251df33cd44ad079ac745eb444a9a14b565904c4e90
ssdeep: 3072:F/oklspDTua83ZJh1rFDmh6idhTy3xAaf9BEJ:LJbrFd6hTy3xAaM
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Title: cure, Author: cure Presentation, Last Saved By: Master Mana, Revision Number: 1, Name of Creating Application: Microsoft Office PowerPoint, Total Editing Time: 03:09, Create Time/Date: Sun Nov 1 23:20:18 2020, Last Saved Time/Date: Sun Nov 1 23:23:27 2020, Number of Words: 0

Version Info:

0: [No Data]

TrojanDownloader:O97M/Obfuse.PM!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35050705
FireEyeTrojan.GenericKD.35050705
McAfeeRDN/Generic.rp
VIPRELooksLike.Macro.Malware.d (v)
AegisLabTrojan.MSOffice.SLoad.a!c
TrendMicroTrojan.P97M.WOREFLINT.AA
CyrenTrojan.IVWW-1
SymantecW97M.Downloader
ESET-NOD32a variant of Generik.EKQUMXJ
TrendMicro-HouseCallTrojan.P97M.WOREFLINT.AA
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Trojan-Downloader.MSOffice.SLoad.gen
BitDefenderTrojan.GenericKD.35050705
ViRobotPPT.Z.Agent.256512
TencentHeur.Macro.Generic.h.7efeb4d9
Ad-AwareTrojan.GenericKD.35050705
EmsisoftTrojan.GenericKD.35050705 (B)
F-SecureMalware.W97M/Dldr.Sload.xmaxl
InvinceaTroj/DocDl-ABDK
McAfee-GW-EditionBehavesLike.OLE2.Downloader.dr
SophosTroj/DocDl-ABDK
IkarusTrojan.VBA.Agent
AviraW97M/Dldr.Sload.xmaxl
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.hma
MicrosoftTrojanDownloader:O97M/Obfuse.PM!MTB
GridinsoftTrojan.U.Downloader.oa
ArcabitTrojan.Generic.D216D4D1
ZoneAlarmHEUR:Trojan-Downloader.MSOffice.SLoad.gen
GDataTrojan.GenericKD.35050705
CynetMalicious (score: 85)
ALYacTrojan.Downloader.PPT.Agent
ZonerProbably Heur.W97Obfuscated
RisingMalware.ObfusVBA@ML.100 (VBA)
SentinelOneDFI – Malicious OLE
FortinetVBA/Agent.HMAOBGZ!tr
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Downloader.3f4

How to remove TrojanDownloader:O97M/Obfuse.PM!MTB?

TrojanDownloader:O97M/Obfuse.PM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment