Trojan

What is “Trojan:Win32/OffLoader.ASU!MTB”?

Malware Removal

The Trojan:Win32/OffLoader.ASU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.ASU!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/OffLoader.ASU!MTB?


File Info:

name: CBE7CA186FD2DD8072CE.mlw
path: /opt/CAPEv2/storage/binaries/edd930ef302a63732da600278bd9182b8102c65c6b2deffa66f4371d3556c05a
crc32: E530CC8D
md5: cbe7ca186fd2dd8072ce0f647c561180
sha1: 72ccde68b11836cc839ccd198b295b245544677a
sha256: edd930ef302a63732da600278bd9182b8102c65c6b2deffa66f4371d3556c05a
sha512: b2483d9b694a5882feebe40b86cd8e32b04df56cfa85893748e9092793be93690e27352a648277910ebf7363c5d9b6d87071495f2549ef655d2f590e498b85f1
ssdeep: 98304:ykLQoYWh8JAV/VH97F3tlQ+1t29s4C1eH9m:dxQJAZVdVQ+1t5o9m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CDE5F13FF268A13ED5AA1B3245738360997B7A51A81A8C0F47FC384CCF765601E3B656
sha3_384: a0f0fb41f8a62da361b28e4cbef8798173bacb322c4c388076c3ec747bad46668111e2258ffe7be969d68e82776356fd
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: JetSmartFilters v323 WordPress Plugin WordPress Plugin.exe S
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: JetSmartFilters v323 WordPress Plugin WordPress Plugin.exe
ProductVersion: 5.0
Translation: 0x0000 0x04b0

Trojan:Win32/OffLoader.ASU!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OffLoader.a!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeTrojan.GenericKD.70499023
SkyhighBehavesLike.Win32.Jeefo.wc
ALYacTrojan.GenericKD.70499023
MalwarebytesAdware.Bundler
SangforDownloader.Win32.Offloader.Vjqd
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDownloader:Win32/OffLoader.7df799f0
K7GWRiskware ( 00584baa1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GWO
APEXMalicious
KasperskyTrojan-Downloader.Win32.OffLoader.acta
BitDefenderTrojan.GenericKD.70499023
NANO-AntivirusTrojan.Win32.OffLoader.keqjqa
MicroWorld-eScanTrojan.GenericKD.70499023
AvastWin32:Malware-gen
TencentWin32.Trojan-Downloader.Offloader.Ewnw
EmsisoftTrojan.GenericKD.70499023 (B)
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.DownLoad4.15944
VIPRETrojan.GenericKD.70499023
TrendMicroTrojan.Win32.DLOADER.UAIO
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Agent
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Downloader.Gen
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/OffLoader.ASU!MTB
ArcabitTrojan.Generic.D433BACF
ZoneAlarmTrojan-Downloader.Win32.OffLoader.acta
GDataTrojan.GenericKD.70499023
VaristW32/OffLoader.B.gen!Eldorado
McAfeeArtemis!CBE7CA186FD2
MAXmalware (ai score=82)
VBA32TrojanDownloader.OffLoader
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.DLOADER.UAIO
RisingDownloader.Agent/IFPS!1.E9EC (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.0360!tr
AVGWin32:Malware-gen
Cybereasonmalicious.8b1183
DeepInstinctMALICIOUS

How to remove Trojan:Win32/OffLoader.ASU!MTB?

Trojan:Win32/OffLoader.ASU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment