Trojan

About “Trojan:Win32/OffLoader.GPD!MTB” infection

Malware Removal

The Trojan:Win32/OffLoader.GPD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.GPD!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan:Win32/OffLoader.GPD!MTB?


File Info:

name: BBD9FA2BE54EE50360E7.mlw
path: /opt/CAPEv2/storage/binaries/1ce56eb6fe43db0d4f319099704faabb06c912c30f1ee283b605b68f95169dda
crc32: 5694B5CF
md5: bbd9fa2be54ee50360e79db901f3811b
sha1: 1d086e894bd64b3fbea350ea61b985da2ec79df0
sha256: 1ce56eb6fe43db0d4f319099704faabb06c912c30f1ee283b605b68f95169dda
sha512: 27f3ca91383bb8a07d124e44782796047dfb864079ba569dc81a1a7dc71a1c6468c8b6993e904a03f8ea0c6a88e98f5c995caba7d6018a3cc8b25b4fceedd29b
ssdeep: 1536:bferrLkSRoe8C4UZsys0Dh1duH4Romu/Tqik9uL7010n6BB2FI+Pl2:bfi3k+oWDBDh1duH45Pikq70+n6XLWl2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF83D011F7A0C077D6B61772283B37B74FB69C2502A0AB430360AE6E7CA2641D91F769
sha3_384: 6d57ea83640c0261b7c7d18c7233186226ee1be748314718b0ba5394464a8324c55ca9e989a4c2ec722b4247f901f44e
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:48

Version Info:

0: [No Data]

Trojan:Win32/OffLoader.GPD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OffLoader.a!c
MicroWorld-eScanGen:Variant.Nemesis.31935
FireEyeGen:Variant.Nemesis.31935
SkyhighRDN/Generic Downloader.x
McAfeeRDN/Generic Downloader.x
MalwarebytesGeneric.Malware/Suspicious
SangforDownloader.Win32.Offloader.Vp7m
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanDownloader:Win32/OffLoader.dc71a9b8
SymantecTrojan.Gen.MBT
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
BitDefenderGen:Variant.Nemesis.31935
AvastNSIS:DropperX-gen [Drp]
EmsisoftGen:Variant.Nemesis.31935 (B)
VIPREGen:Variant.Nemesis.31935
TrendMicroTrojan.Win32.OFFLOADER.USBLC124
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataGen:Variant.Nemesis.31935
VaristW32/Trojan.WMIT-7221
Antiy-AVLTrojan[Downloader]/Win32.OffLoader.gen
KingsoftWin32.Trojan-Downloader.OffLoader.gen
ArcabitTrojan.Nemesis.D7CBF
ZoneAlarmHEUR:Trojan-Downloader.Win32.OffLoader.gen
MicrosoftTrojan:Win32/OffLoader.GPD!MTB
GoogleDetected
ALYacGen:Variant.Nemesis.31935
MAXmalware (ai score=82)
VBA32suspected of Trojan.Downloader.gen
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojan.Win32.OFFLOADER.USBLC124
AVGNSIS:DropperX-gen [Drp]
Cybereasonmalicious.94bd64
DeepInstinctMALICIOUS

How to remove Trojan:Win32/OffLoader.GPD!MTB?

Trojan:Win32/OffLoader.GPD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment