Trojan

Trojan:Win32/Offloader.CCHL!MTB information

Malware Removal

The Trojan:Win32/Offloader.CCHL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Offloader.CCHL!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan:Win32/Offloader.CCHL!MTB?


File Info:

name: E3770BDF4BD389BAC42F.mlw
path: /opt/CAPEv2/storage/binaries/e2926870180c5fb58f90e5a1e3aeaceeb7736b354e28114322c1adb48c748741
crc32: E8833190
md5: e3770bdf4bd389bac42ff8a1365899f2
sha1: 9e8b68750a73f2f06e9b2bd08665c076af5a8f3c
sha256: e2926870180c5fb58f90e5a1e3aeaceeb7736b354e28114322c1adb48c748741
sha512: 53917314199ba47eb05f6eebce8e4f0e47c8ccbd132783b68765e350787b1ed6024a19a767a5f6b95b601d98713569266efa53c0d1a150070bb74d77d3b5c266
ssdeep: 6144:2Qqk6O2TjgVt9ZJLmjcLQp22N/G1JQxhhdoK+tlito0l:16Pjghmjccp22YJahht+tlM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF54237D32C6ECF6D57B54F09867EABF93B79212230116631762BE2FAD35083A429181
sha3_384: d65634ce28e0e6e5574f9e50679ef67f91fbbbb72c44a5c6429890302461ba3255edf471a42846d032d5d15f04be5159
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

0: [No Data]

Trojan:Win32/Offloader.CCHL!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Nemesis.31433
FireEyeGen:Variant.Nemesis.31433
SkyhighBehavesLike.Win32.Suspicious.dc
McAfeeArtemis!E3770BDF4BD3
MalwarebytesMalware.AI.155203746
VIPREGen:Variant.Nemesis.31433
Cybereasonmalicious.50a73f
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Bsymem.gen
BitDefenderGen:Variant.Nemesis.31433
AvastNSIS:TrojanX-gen [Trj]
F-SecureTrojan.TR/Bsymem.tugly
TrendMicroTROJ_GEN.R002C0DBH24
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Nemesis.31433 (B)
IkarusTrojan-Downloader.NSIS.Adload
GDataGen:Variant.Nemesis.31433
GoogleDetected
AviraTR/Bsymem.tugly
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Nemesis.D7AC9
ZoneAlarmHEUR:Trojan.Win32.Bsymem.gen
MicrosoftTrojan:Win32/Offloader.CCHL!MTB
VaristW32/Downloader.SNXK-4798
ALYacGen:Variant.Nemesis.31433
MAXmalware (ai score=80)
VBA32suspected of Trojan.Downloader.gen
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DBH24
FortinetNSIS/Adload.DS!tr
AVGNSIS:TrojanX-gen [Trj]
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Trojan:Win32/Offloader.CCHL!MTB?

Trojan:Win32/Offloader.CCHL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment