Trojan

Trojan:Win32/OffLoader.GE!MTB removal guide

Malware Removal

The Trojan:Win32/OffLoader.GE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.GE!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan:Win32/OffLoader.GE!MTB?


File Info:

name: A6CB313E65EE33272373.mlw
path: /opt/CAPEv2/storage/binaries/fb17ebab9fcee76a6c9a5eb30cc8287e40d4e25a3b8e79531f33f4e01472343f
crc32: 0CC13170
md5: a6cb313e65ee33272373789b685e5c55
sha1: 34ba4f5bed24ffde8eb2025e93f901c51fc5e115
sha256: fb17ebab9fcee76a6c9a5eb30cc8287e40d4e25a3b8e79531f33f4e01472343f
sha512: 493dac556d2178e2271caf12a0eececd4ce3a4bce8c45454c0accf7809bfcc30f7d9bfb21fcffc652a1473322493e3bd91e5400d44eac29ee417553283a07ddb
ssdeep: 1536:rferrLkSRoe8C4UZsys0Dh1duq4Romu/7qPXrKQ4hs0DRzFI+Pl3:rfi3k+oWDBDh1duq45LPmPFiWl3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11763BF11F350C073D9B25332683A2BAB5FF6992252A49B0743907F1E7CA2681ED1F7A5
sha3_384: 99f8b9deafc1819ecd44b312f2a12f9a8358e1cf2b1be76d140cede1966528659e01de5e74ddde6add62966cc61eb54f
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:48

Version Info:

0: [No Data]

Trojan:Win32/OffLoader.GE!MTB also known as:

BkavW32.Common.8C8D0456
LionicTrojan.Win32.OffLoader.a!c
CynetMalicious (score: 99)
FireEyeTrojan.Generic.35321959
SkyhighRDN/Generic Downloader.x
McAfeeRDN/Generic Downloader.x
Cylanceunsafe
VIPRETrojan.Generic.35321959
SangforDownloader.Win32.Offloader.Vukw
K7AntiVirusTrojan-Downloader ( 005b222d1 )
AlibabaTrojanDownloader:Win32/OffLoader.29661cad
K7GWTrojan-Downloader ( 005b222d1 )
VirITTrojan.Win32.NSISDrp.CHQB
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.HNK
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
BitDefenderTrojan.Generic.35321959
MicroWorld-eScanTrojan.Generic.35321959
AvastNSIS:DropperX-gen [Drp]
TencentWin32.Trojan-Downloader.Oader.Yfow
EmsisoftTrojan.Generic.35321959 (B)
F-SecureTrojan.TR/Adload.Gen
DrWebTrojan.DownLoad4.16271
TrendMicroTROJ_GEN.R03BC0DC824
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.NSIS.Adload
GoogleDetected
AviraTR/Adload.Gen
Antiy-AVLTrojan[Downloader]/Win32.OffLoader.gen
KingsoftWin32.Trojan-Downloader.OffLoader.gen
MicrosoftTrojan:Win32/OffLoader.GE!MTB
ArcabitTrojan.Generic.D21AF867
ZoneAlarmHEUR:Trojan-Downloader.Win32.OffLoader.gen
GDataTrojan.Generic.35321959
VaristW32/Trojan.CZNG-2275
ALYacTrojan.Generic.35321959
MAXmalware (ai score=83)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesTrojan.AdLoad.Generic
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0DC824
FortinetNSIS/Agent.HNK!tr
AVGNSIS:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[downloader]:Win/OffLoader.GE!MTB

How to remove Trojan:Win32/OffLoader.GE!MTB?

Trojan:Win32/OffLoader.GE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment