Trojan

About “Trojan-Downloader.Win32.OffLoader.ozs” infection

Malware Removal

The Trojan-Downloader.Win32.OffLoader.ozs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.OffLoader.ozs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.OffLoader.ozs?


File Info:

name: 39A625EB53A2E8B1EB1C.mlw
path: /opt/CAPEv2/storage/binaries/b563cf483cc5cde3afa9b391064c47af0bbce87514c4d5f0a1d16bd3a8e4905c
crc32: 5139FC2A
md5: 39a625eb53a2e8b1eb1cf830655befde
sha1: ae8f91e5cb634106768d7da9fc58c828a503facc
sha256: b563cf483cc5cde3afa9b391064c47af0bbce87514c4d5f0a1d16bd3a8e4905c
sha512: bee8c3800800e2ecf0cc42453396b8f5845ec59b43536acc33b983a6b290db73aa4e43c0b4c228d524773d62031744aadc24f369d723b2f93d3368b46d86f794
ssdeep: 98304:ykL/oYWh8JAV/VH97F3tlQ+Yt29s4C1eH9e:dgQJAZVdVQ+Yt5o9e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6E5F13FF268A13EC5AA1B3245738260997B7A51A81A8C0F47FC384DCF765701E3B656
sha3_384: 2da4d221e6b0d46d734d630dd60bab43785a24e5020bbe00fd69f85c2b90909c153ac672acae12f4f1aac42c16269284
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Tweak-SSD Pro 2070 Portable Optimization SCloudWS.exe Set
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Tweak-SSD Pro 2070 Portable Optimization SCloudWS.exe
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.OffLoader.ozs also known as:

BkavW32.AIDetectMalware
Cybereasonmalicious.5cb634
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.OffLoader.ozs
TencentMalware.Win32.Gencirc.10bf1845
F-SecureTrojan.TR/Downloader.Gen
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
WebrootW32.Trojan.Gen
AviraTR/Downloader.Gen
ZoneAlarmTrojan-Downloader.Win32.OffLoader.ozs
MicrosoftTrojan:Script/Phonzy.B!ml
FortinetW32/Agent.0360!tr
AVGWin32:Malware-gen

How to remove Trojan-Downloader.Win32.OffLoader.ozs?

Trojan-Downloader.Win32.OffLoader.ozs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment