Trojan

Trojan:Win32/OffLoader.ASY!MTB malicious file

Malware Removal

The Trojan:Win32/OffLoader.ASY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.ASY!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/OffLoader.ASY!MTB?


File Info:

name: E312CC55E22B5139186A.mlw
path: /opt/CAPEv2/storage/binaries/d7821a396179be2ae9fbbffc53968215c6d1a3981d7f5c9819b661f91c89a18c
crc32: BA6748F7
md5: e312cc55e22b5139186aa1120633fb22
sha1: 6c83acbb998334713274632d222b25be5731d9a0
sha256: d7821a396179be2ae9fbbffc53968215c6d1a3981d7f5c9819b661f91c89a18c
sha512: ff5919e73bb5c06a3e7aee4023004969003a16f965e5fdf122c212ea8318dc6ff00ee67879db0267e9f278c06dafbd37c4eca34c5e96a0fabfbecb7686ad56e2
ssdeep: 24576:s7FUDowAyrTVE3U5F/enDLKic6QL3E2vVsjECUAQT45deRV9Rm:sBuZrEUkPKIy029s4C1eH90
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10275BF3FF268A13EC5AA1B3245B38310997BBA51B81A8C1E47FC344DCF765601E3B656
sha3_384: b0ed63855146fe0a14496c5ada1478361bd2005021e521a0ca8af0141ae6bed5b9441f7d94493dd2d9e5a07e7ba98b79
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: MethodA
FileDescription: W10 Digital Activation 153 Portable by Ratiborus Activators
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: W10 Digital Activation 153 Portable by Ratiborus Activators
ProductVersion: 12.05
Translation: 0x0000 0x04b0

Trojan:Win32/OffLoader.ASY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OffLoader.a!c
SkyhighBehavesLike.Win32.Trojan.tc
McAfeeArtemis!E312CC55E22B
MalwarebytesGeneric.Malware/Suspicious
SangforDownloader.Win32.Offloader.Vh26
K7AntiVirusTrojan-Downloader ( 005ae1811 )
AlibabaTrojanDownloader:Win32/OffLoader.d4e59bbc
K7GWTrojan-Downloader ( 005ae1811 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.HIV
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan-Downloader.Win32.OffLoader.aqux
AvastWin32:Malware-gen
TencentWin32.Trojan-Downloader.Oader.Ximw
SophosMal/Generic-S
F-SecureTrojan.TR/Downloader.Gen
TrendMicroTROJ_GEN.R002C0DA224
IkarusTrojan-Downloader
VaristW32/Agent.HTI.gen!Eldorado
AviraTR/Downloader.Gen
MicrosoftTrojan:Win32/OffLoader.ASY!MTB
ViRobotTrojan.Win.Z.Offloader.1672084
ZoneAlarmTrojan-Downloader.Win32.OffLoader.aqux
GDataWin32.Trojan.Agent.J6ZAFL
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.R629038
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DA224
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.HIV!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/OffLoader.ASY!MTB?

Trojan:Win32/OffLoader.ASY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment