Trojan

Trojan:Win32/OffLoader.GDAA!MTB removal

Malware Removal

The Trojan:Win32/OffLoader.GDAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.GDAA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan:Win32/OffLoader.GDAA!MTB?


File Info:

name: 877D2C24E882187E4DF5.mlw
path: /opt/CAPEv2/storage/binaries/d7bcbd95835beec54d0fbfeda044568064a544f0822f0dcd943d295983b7a2e0
crc32: 4893D674
md5: 877d2c24e882187e4df5eed400702394
sha1: c5f498d285f822dc95fe0995b7e7ff938baef22d
sha256: d7bcbd95835beec54d0fbfeda044568064a544f0822f0dcd943d295983b7a2e0
sha512: 60df9fbd187efeaace13f3fcedf105d0550748a90e1b68564e06c51d49678d11572882f88d97f6c937afbe9b0a362f879bd8ba06e60201114fe7259d3e42aa6e
ssdeep: 1536:bferrLkSRoe8C4UZsys0Dh1duH4Romu/TqZjo9uL7010n6BB2FI+PlN:bfi3k+oWDBDh1duH45Peq70+n6XLWlN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC83D011F790C0B7D6B61371683B37B74FE6982502A09B4703607E2EBC72681D91F7A9
sha3_384: 46dd6e2b3aa6c301bb640c15994c72693edbe16da5214da4b20f44ecdd756dac72447dd0159597997dbebba80c519bd4
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:48

Version Info:

0: [No Data]

Trojan:Win32/OffLoader.GDAA!MTB also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
MicroWorld-eScanGen:Variant.Nemesis.31933
FireEyeGen:Variant.Nemesis.31933
SkyhighBehavesLike.Win32.BadFile.lc
McAfeeArtemis!877D2C24E882
VIPREGen:Variant.Nemesis.31933
Cybereasonmalicious.285f82
SymantecTrojan.Gen.MBT
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
BitDefenderGen:Variant.Nemesis.31933
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Nemesis.31933 (B)
F-SecureTrojan.TR/Redcap.ruxbk
TrendMicroTrojan.Win32.OFFLOADER.USBLBT24
Trapminemalicious.moderate.ml.score
GoogleDetected
AviraTR/Redcap.ruxbk
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.OffLoader.gen
Kingsoftmalware.kb.a.839
MicrosoftTrojan:Win32/OffLoader.GDAA!MTB
ArcabitTrojan.Nemesis.D7CBD
ZoneAlarmHEUR:Trojan-Downloader.Win32.OffLoader.gen
GDataGen:Variant.Nemesis.31933
VaristW32/Trojan.WMIT-7221
ALYacGen:Variant.Nemesis.31933
VBA32suspected of Trojan.Downloader.gen
Cylanceunsafe
TrendMicro-HouseCallTrojan.Win32.OFFLOADER.USBLBT24
FortinetNSIS/Dropper.X!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Trojan:Win32/OffLoader.GDAA!MTB?

Trojan:Win32/OffLoader.GDAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment