Trojan

How to remove “TrojanDownloader:O97M/Obfuse.PXR!MTB”?

Malware Removal

The TrojanDownloader:O97M/Obfuse.PXR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/Obfuse.PXR!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:O97M/Obfuse.PXR!MTB?


File Info:

crc32: F581BDFD
md5: daea44be59abc7fb93789c9ec9535bdf
name: upload_file
sha1: cddfa3986d6bbe84d4b849b3d681bae5377de81d
sha256: 93727c5cfbe727e43f0644f888fddb03c4f5728f82c74952981691f09de44642
sha512: 361caf9960a24b831968935337eb9b191fabab697697b3e6240f2fcaa1be0c4f4826ad279ebc0b655b2a2b7c7030b3f6c6cc020c2461153c69564c6abf2497fc
ssdeep: 6144:Kk3hOdsylKlgryzc4bNhZF+E+W2knF+AqmFkM9lz2KE8hBdLVoo5z9Nn/FDC5GV:V5kMHq/8oo5ztOcVLEP9iYtHliEM9fG
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: DELL, Last Saved By: DELL, Create Time/Date: Thu Aug 13 00:22:51 2020, Last Saved Time/Date: Thu Aug 13 00:22:51 2020, Security: 0

Version Info:

0: [No Data]

TrojanDownloader:O97M/Obfuse.PXR!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34352218
FireEyeTrojan.GenericKD.34352218
McAfeeRDN/Generic Downloader.x
AegisLabTrojan.MSExcel.Generic.4!c
SangforMalware
SymantecTrojan.Gen.2
AvastSNH:Script [Dropper]
ClamAVXls.Dropper.Agent-9317203-0
KasperskyHEUR:Trojan-Downloader.MSOffice.SLoad.gen
BitDefenderTrojan.GenericKD.34352218
ViRobotXLS.Z.Agent.389120.G
RisingDownloader.Agent/VBA!1.C970 (CLASSIC)
Ad-AwareTrojan.GenericKD.34352218
F-SecureMalware.VBA/Dldr.Agent.ylbmu
DrWebExploit.Siggen2.17439
FortinetVBA/Agent.GAK!tr.dldr
SophosTroj/DocDl-AABN
IkarusTrojan-Downloader.VBA.Agent
AviraVBA/Dldr.Agent.ylbmu
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.txv
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmHEUR:Trojan-Downloader.MSOffice.SLoad.gen
MicrosoftTrojanDownloader:O97M/Obfuse.PXR!MTB
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.34352218
TACHYONSuspicious/X97M.Downloader.Gen
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.TXV
TencentHeur.Macro.Generic.e.aaa7fb6f
SentinelOneDFI – Suspicious OLE
GDataTrojan.GenericKD.34352218
AVGSNH:Script [Dropper]
Qihoo-360Generic/Trojan.Downloader.3f4

How to remove TrojanDownloader:O97M/Obfuse.PXR!MTB?

TrojanDownloader:O97M/Obfuse.PXR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment