Trojan

What is “TrojanDownloader:O97M/Obfuse.YAJ!MTB”?

Malware Removal

The TrojanDownloader:O97M/Obfuse.YAJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:O97M/Obfuse.YAJ!MTB virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine TrojanDownloader:O97M/Obfuse.YAJ!MTB?


File Info:

crc32: 695326A7
md5: 4f4b085463f4a8885497de8cbcc2aceb
name: upload_file
sha1: a59370e6143369be9c017970158e4e7db617554a
sha256: eac82994777b64301341675612fcacac8f08af9d468014c8de9f15aa3c784b42
sha512: bc3bfca5e6b15c7354c40447681db191f1ba2d2dd18df696606afcbcc04591295b01d7faf6cdbde13ce06b04b8d6b343abaa23a90c404ba51bf8ff4f6740bb3d
ssdeep: 12288:f2+NJ9iY+2yy/RJVSjlWRKTZ01lQhO8M0KiT:f2+NJ9iYgqjABgeZiQ7pKiT
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Author: Dell, Last Saved By: Dell, Create Time/Date: Mon Oct 5 08:14:01 2020, Last Saved Time/Date: Mon Oct 5 08:14:01 2020, Security: 0

Version Info:

0: [No Data]

TrojanDownloader:O97M/Obfuse.YAJ!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43985760
FireEyeTrojan.GenericKD.43985760
CAT-QuickHealXMLS.VBAPurging.38956
ALYacTrojan.GenericKD.43985760
InvinceaTroj/DocDl-AAUJ
CyrenX97M/Agent.HP
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.X97M.POWLOAD.ANFOGEP
AvastVBA:Downloader-BLX [Trj]
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderTrojan.GenericKD.43985760
Ad-AwareTrojan.GenericKD.43985760
EmsisoftTrojan.GenericKD.43985760 (B)
ComodoMalware@#21sre6s7v4zyh
F-SecureMalware.VBS/Dldr.Agent.CK
DrWebExploit.Siggen2.47662
TrendMicroTrojan.X97M.POWLOAD.ANFOGEP
McAfee-GW-EditionBehavesLike.OLE2.Downloader.gb
SophosTroj/DocDl-AAUJ
AviraVBS/Dldr.Agent.CK
MicrosoftTrojanDownloader:O97M/Obfuse.YAJ!MTB
ArcabitHEUR.VBA.CG.1
ViRobotX97M.S.Agent.462848.A
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataTrojan.GenericKD.43985760
CynetMalicious (score: 85)
AhnLab-V3Downloader/MSOffice.Agent
McAfeeRDN/Generic Downloader.x
ZonerProbably Heur.W97Obfuscated
ESET-NOD32GenScript.KJB
IkarusTrojan.Office.Doc
FortinetVBA/Agent.BLX!tr.dldr
AVGVBA:Downloader-BLX [Trj]
Qihoo-360Generic/Trojan.Downloader.251

How to remove TrojanDownloader:O97M/Obfuse.YAJ!MTB?

TrojanDownloader:O97M/Obfuse.YAJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment