Trojan

Trojan-Downloader.Win32.OffLoader.yry information

Malware Removal

The Trojan-Downloader.Win32.OffLoader.yry is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.OffLoader.yry virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.OffLoader.yry?


File Info:

name: 97B0CA2AC10887D482D9.mlw
path: /opt/CAPEv2/storage/binaries/4cc41a208384d82fa2668b79f386a0fdd59a46e3fb98d4442bc8436d4917dceb
crc32: A1B5F1E9
md5: 97b0ca2ac10887d482d9d9d7e57a44bc
sha1: eba3456b85e0045bab7ae4a2103202a9d4da824d
sha256: 4cc41a208384d82fa2668b79f386a0fdd59a46e3fb98d4442bc8436d4917dceb
sha512: 25789b3766302bc2044f8a107f5044827f3526a0590f9c096cb2024b313e607aa0175b5962567f4742bd32e5e4ca170774fbd4841e136634b59bff3ebe6060e5
ssdeep: 98304:ykLvoYWh8JAV/VH97F3tlQ+Qt29s4C1eH9J:dQQJAZVdVQ+Qt5o9J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185E5F13FF268A13EC4AE1B3245739260997B7A51A81A8C0F47FC384DCF765601E3B656
sha3_384: 542ee661a499174567bcb946c58e5dcab71059fd68dbf421ce0d5a742b733ea5c0b9c8fe915a277628eeaccd342e70cc
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Vega20Clicker.exe Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Vega20Clicker.exe
ProductVersion: 3.58
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.OffLoader.yry also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Pate.wc
Cylanceunsafe
SangforDownloader.Win32.Offloader.Vvj3
K7AntiVirusTrojan-Downloader ( 005a547b1 )
K7GWTrojan-Downloader ( 005a547b1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GWO
KasperskyTrojan-Downloader.Win32.OffLoader.yry
AlibabaTrojanDownloader:Win32/OffLoader.586adb2a
ViRobotTrojan.Win.Z.Agent.3261493.A
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.DownLoad4.15944
SophosMal/Generic-S
IkarusTrojan.Inno.Agent
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Downloader.Gen
VaristW32/OffLoader.B.gen!Eldorado
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmTrojan-Downloader.Win32.OffLoader.yry
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Malware-gen.C5525521
McAfeeArtemis!97B0CA2AC108
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0AJQ23
TencentMalware.Win32.Gencirc.10bf1845
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.0360!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b85e00
AvastWin32:Malware-gen

How to remove Trojan-Downloader.Win32.OffLoader.yry?

Trojan-Downloader.Win32.OffLoader.yry removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment