Trojan

Trojan:Win32/Offloader.G!MTB information

Malware Removal

The Trojan:Win32/Offloader.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Offloader.G!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan:Win32/Offloader.G!MTB?


File Info:

name: ECFD8D1FA9F4FFB49684.mlw
path: /opt/CAPEv2/storage/binaries/b0293b3d296341c523ac2d3d8f4f41e789bd04e40e5648a36ff86732ed52d29c
crc32: 37BD3F25
md5: ecfd8d1fa9f4ffb496846c0dcb850e60
sha1: 876641001612288af1f17fe4523a3851f2b29a61
sha256: b0293b3d296341c523ac2d3d8f4f41e789bd04e40e5648a36ff86732ed52d29c
sha512: 18a75750380521b4874158b2de7d83fa9951835b0be21fc11d8a6323459417f727b4d18aee8793f4a952ac66a3fc51167b3f3429225a74a99726e8bdbb4dca47
ssdeep: 24576:s7FUDowAyrTVE3U5F/+GqK+Kic6QL3E2vVsjECUAQT45deRV9RB:sBuZrEUzkKIy029s4C1eH9L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F85CF3FF268A13EC46A1B3245739320997BBA61B81A8C1E47FC344DCF765601E3B656
sha3_384: 64e177e9b8c0e0474b0477c4730b0ef9c6a4c54f6a3dc9506b660ad16cb6b29e76f2841536a7a2e6e5cc86634fd9fa20
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Five Nights of Passion VR v132 By TheDarck67.exe Setup
FileVersion: 5.5.0.0
LegalCopyright: Five Nights of Passion VR v132 By TheDarck67.exe
OriginalFileName:
ProductName: Five Nights of Passion VR v132 By TheDarck67.exe
ProductVersion: 5.5.0.0
Translation: 0x0000 0x04b0

Trojan:Win32/Offloader.G!MTB also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoad4.16298
SkyhighBehavesLike.Win32.Trojan.tc
McAfeeArtemis!ECFD8D1FA9F4
MalwarebytesGeneric.Malware/Suspicious
SangforDownloader.Win32.Offloader.Vomi
K7AntiVirusTrojan-Downloader ( 005adf841 )
AlibabaTrojanDownloader:Win32/OffLoader.e15739f4
K7GWTrojan-Downloader ( 005adf841 )
CrowdStrikewin/malicious_confidence_90% (D)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.HIO
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0ADE24
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
AvastFileRepMalware [Misc]
F-SecureHeuristic.HEUR/AGEN.1372992
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraHEUR/AGEN.1372992
VaristW32/OffLoader.A.gen!Eldorado
MicrosoftTrojan:Win32/Offloader.G!MTB
ZoneAlarmHEUR:Trojan-Downloader.Win32.OffLoader.gen
GDataWin32.Trojan.Agent.TOE8RZ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5613656
Cylanceunsafe
PandaTrj/Chgt.AD
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Agent
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/OffLoader.gen

How to remove Trojan:Win32/Offloader.G!MTB?

Trojan:Win32/Offloader.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment