Trojan

Trojan:Win32/OffLoader.GF!MTB information

Malware Removal

The Trojan:Win32/OffLoader.GF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.GF!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan:Win32/OffLoader.GF!MTB?


File Info:

name: 148A6C3C3A419ECA4410.mlw
path: /opt/CAPEv2/storage/binaries/8988985cdc00357bf5bbea6b29f665536d1a0aea09bfc1bc8239f17831124638
crc32: F79C05D5
md5: 148a6c3c3a419eca4410aef1fdcd6b0a
sha1: c37810d812a089a0456975608402004baa18f8f0
sha256: 8988985cdc00357bf5bbea6b29f665536d1a0aea09bfc1bc8239f17831124638
sha512: 2fffe50dccdc0880d1bf0a2d3b4c5c669ad0bbfcba379b27e9be9e910ff705ff0d3fb73f4296ae11580d768c14a8a40413d2c0c1a05dcc4b11075fe2e84b416d
ssdeep: 1536:rferrLkSRoe8C4UZsys0Dh1duq4Romu/7qV5FI+PlV:rfi3k+oWDBDh1duq45LuWlV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC63BF01E390C073D9F21371683A2BB75FF6992552A49B0343907F2E7CA2681ED1FBA5
sha3_384: 62d1f9be524dc5b37d7fe174d3e567c59babc71f011c110685c936aaa26e9ddc2ebe2115d3ef1e0e2c74e2e433317bac
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:48

Version Info:

0: [No Data]

Trojan:Win32/OffLoader.GF!MTB also known as:

BkavW32.Common.2FAD8074
LionicTrojan.Win32.OffLoader.a!c
MicroWorld-eScanTrojan.Generic.35319918
FireEyeTrojan.Generic.35319918
SkyhighBehavesLike.Win32.BadFile.kh
McAfeeArtemis!148A6C3C3A41
MalwarebytesTrojan.Downloader.NSIS
SangforDownloader.Win32.Offloader.Vbin
AlibabaTrojanDownloader:Win32/OffLoader.d7e460dc
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.NSISDrp.CHQB
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDownloader.Agent.HNK
TrendMicro-HouseCallTROJ_GEN.R002C0DC824
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
BitDefenderTrojan.Generic.35319918
AvastNSIS:DropperX-gen [Drp]
TencentWin32.Trojan-Downloader.Oader.Najl
EmsisoftTrojan.Generic.35319918 (B)
F-SecureTrojan.TR/Adload.Gen
DrWebTrojan.DownLoad4.16208
VIPRETrojan.Generic.35319918
TrendMicroTROJ_GEN.R002C0DC824
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GoogleDetected
AviraTR/Adload.Gen
VaristW32/Trojan.CZNG-2275
Antiy-AVLTrojan[Downloader]/Win32.OffLoader.gen
KingsoftWin32.Trojan-Downloader.OffLoader.gen
MicrosoftTrojan:Win32/OffLoader.GF!MTB
ArcabitTrojan.Generic.D21AF06E
ZoneAlarmHEUR:Trojan-Downloader.Win32.OffLoader.gen
GDataTrojan.Generic.35319918
CynetMalicious (score: 100)
VBA32TrojanDownloader.OffLoader
MAXmalware (ai score=81)
Cylanceunsafe
PandaTrj/Chgt.AD
IkarusTrojan-Downloader.NSIS.Adload
FortinetNSIS/Agent.HNK!tr
AVGNSIS:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/OffLoader.GF!MTB?

Trojan:Win32/OffLoader.GF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment