Trojan

Should I remove “Trojan:Win32/OffLoader.GPD!MTB”?

Malware Removal

The Trojan:Win32/OffLoader.GPD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.GPD!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Trojan:Win32/OffLoader.GPD!MTB?


File Info:

name: 7B5206430041760625BA.mlw
path: /opt/CAPEv2/storage/binaries/2918040df8c351c44b8f6c57eb4eaf3eea8bfe862a22faf9c85c0dfce5215070
crc32: 676B1D2D
md5: 7b5206430041760625ba231fc241e448
sha1: dfd7e91d9e1cc330c44c1b593c7fa078208e5762
sha256: 2918040df8c351c44b8f6c57eb4eaf3eea8bfe862a22faf9c85c0dfce5215070
sha512: f476288f9d4373f90c39e7b4fcacda796265084c59712ba63e27964cd395e98f3eb4ba0e0ef6282682208f4664e49a396352309d9c4fe84757d4dcdf05e515b7
ssdeep: 196608:DuSMjnFMiNfEXCetZBJvLxRiPoUYwVuRtl1:DPMjn6ip+TBvRiDsRF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FA63336C2E572ABC48F9876521A8EBB2C50BF0E3571B201366515BE60617D2F1BF1F8
sha3_384: b8f25128f552823ea1dbbd6b827749fb8d7a5761437c7e05349afabc9c34e4dcc4115cb745431cb1fa07ba813772ca0d
ep_bytes: 81ecf80300005556576a205f33ed6801
timestamp: 2023-07-02 02:09:48

Version Info:

0: [No Data]

Trojan:Win32/OffLoader.GPD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OffLoader.a!c
MicroWorld-eScanTrojan.Generic.35330397
SkyhighBehavesLike.Win32.BadFile.tc
McAfeeArtemis!7B5206430041
MalwarebytesGeneric.Malware/Suspicious
VIPRETrojan.Generic.35330397
SangforDropper.Win32.Offloader.V2yd
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDownloader:Win32/OffLoader.dacc036a
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.300417
VirITTrojan.Win32.NSISDrp.CHQB
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/TrojanDownloader.Agent.OBN
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03BC0DC424
KasperskyHEUR:Trojan-Downloader.Win32.OffLoader.gen
BitDefenderTrojan.Generic.35330397
AvastNSIS:DropperX-gen [Drp]
TencentWin32.Trojan-Downloader.Offloader.Ltgl
EmsisoftTrojan.Generic.35330397 (B)
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R03BC0DC424
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.7b52064300417606
SophosMal/Generic-S
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Trojan.WMIT-7221
Antiy-AVLTrojan[Downloader]/Win32.OffLoader.gen
MicrosoftTrojan:Win32/OffLoader.GPD!MTB
ArcabitTrojan.Generic.D21B195D
GDataTrojan.Generic.35330397
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.DropperX-gen.C5594756
VBA32suspected of Trojan.Downloader.gen
ALYacTrojan.Generic.35330397
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Chgt.AD
FortinetW32/PossibleThreat
AVGNSIS:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/OffLoader.GPD!MTB?

Trojan:Win32/OffLoader.GPD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment