Trojan

TrojanDropper:O97M/GraceWire.ARK!MTB removal

Malware Removal

The TrojanDropper:O97M/GraceWire.ARK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:O97M/GraceWire.ARK!MTB virus can do?

  • The office file contains 9 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

How to determine TrojanDropper:O97M/GraceWire.ARK!MTB?


File Info:

crc32: 71DEADB4
md5: 334011ab1d9ae73386d78f60fbdc3d44
name: upload_file
sha1: 68b5754dddef8bcf7c48d29adde3aba068ebfcaa
sha256: 90be40df607eeb01438037ae8a6a642bb39633fdfbc7d8926bee3e9694fe50ba
sha512: 493420b12a3ab9b3aab53b6b9146d2dc173a3dbe0127007b1a90a625f8a0064baca5f12584269e1f715a50bf268a8368f8b454711a9f9204bb52d51b8606d40f
ssdeep: 12288:8o2aJZEy3/AdZOdvfXeGlbU6dRE1eK/KaV+JvT7jYVsi6UqttsQfE4zX6ItaQXS:SajEa/AsfXeGlbldRpKCn77EnFD6uTz
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jun 22 11:41:03 2020, Last Saved Time/Date: Thu Aug 20 11:18:52 2020, Security: 0

Version Info:

0: [No Data]

TrojanDropper:O97M/GraceWire.ARK!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43699222
FireEyeTrojan.GenericKD.43699222
CAT-QuickHealX97M.Downloader.38800
McAfeeW97M/Downloader.dds
AegisLabTrojan.Script.Generic.4!c
SangforMalware
InvinceaTroj/DocDl-AAGO
CyrenPNG/Trojan.USCY-8
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_FRS.0NA103HK20
AvastOther:Malware-gen [Trj]
ClamAVWin.Dropper.Hideproc-6663113-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.43699222
NANO-AntivirusTrojan.Win32.Redcap.hsqoli
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
Ad-AwareTrojan.GenericKD.43699222
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/Macro.Downloader.MRUZ.Gen
DrWebTrojan.DownLoader34.18684
TrendMicroTROJ_FRS.0NA103HK20
SophosTroj/DocDl-AAGO
SentinelOneDFI – Malicious OLE
AviraHEUR/Macro.Downloader.MRUZ.Gen
Antiy-AVLTrojan/Generic.Generic
MicrosoftTrojanDropper:O97M/GraceWire.ARK!MTB
ArcabitTrojan.Generic.D29ACC16
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.43699222
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZedlaF.34216.ty5@aSY3W2ci
ALYacTrojan.Dropper.X97M
TACHYONSuspicious/W97.NS.Gen
VBA32Trojan.Downloader
ZonerProbably Heur.W97Call
ESET-NOD32GenScript.JVI
TencentWin32.Trojan.Generic.Lhmu
FortinetW32/Dropper.GIF!tr
AVGOther:Malware-gen [Trj]
Qihoo-360Generic/Trojan.Script.ed4

How to remove TrojanDropper:O97M/GraceWire.ARK!MTB?

TrojanDropper:O97M/GraceWire.ARK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment