Trojan

Trojan:Win32/Oficla.T removal instruction

Malware Removal

The Trojan:Win32/Oficla.T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Oficla.T virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Trojan:Win32/Oficla.T?


File Info:

name: 82328B8242BACB05B4F2.mlw
path: /opt/CAPEv2/storage/binaries/632d5647f340cf877ae933d65982889d2b50c82a7a7064b301fdf6e8712a6f74
crc32: D4378F88
md5: 82328b8242bacb05b4f2e29b21e48e18
sha1: 99f04562f49e9ca0aea592fe7fab7bcfc2db7f64
sha256: 632d5647f340cf877ae933d65982889d2b50c82a7a7064b301fdf6e8712a6f74
sha512: 8b0f081bf941e4366510a57102c172a1067db24ce6f3817dc4300467a470c56c084659a57ef8e147b7643ae276560f406c57cc6a884cde90577f8b36da88b994
ssdeep: 768:s5D9IERYonVqEn4tQFAL42DKaYlWUaJfoQPRlvQXUFDHuPydVOLKb8e5Bkao+:eJIER1P+L40YPaJfvPfduPydwLKb8RaN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112330194B5794925C9F30FBAFE17E2CF141039095B07B6B4110EB3A17A6728873557A8
sha3_384: f53ef91daf19ecc660169e3b7ac33f85db15f6fa71efb9e1cdef5e6ada3e0f61cb5241a228892f9a03e3f6b62cd9b277
ep_bytes: 60be00c041008dbe0050feff5783cdff
timestamp: 2007-06-17 00:11:12

Version Info:

CompanyName: УюВпЗЧъТЗЭСГмИБЬБутнАъСп
FileDescription: жЕямТыжГыЫГютЖыАОСдЭэыЯ
FileVersion: 115.0.51.99
InternalName: ЗНСкЦЫжЦУуСцнъЫХпМАЩыКбвкт
LegalCopyright: 3047-6530
OriginalFilename: awisepMa.exe
ProductName: гЗВЯВДтчсуЦЯчыИпсЛВлПКЛГрэ
ProductVersion: 115.0.51.99
Translation: 0x04b0 0x0417

Trojan:Win32/Oficla.T also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.4
FireEyeGeneric.mg.82328b8242bacb05
McAfeeGenericRXAA-FA!82328B8242BA
CylanceUnsafe
VIPRETrojan.Win32.Nedsym.f (v)
SangforTrojan.Win32.Krap.hm
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirTool:Win32/Obfuscator.892d53dd
K7GWTrojan ( f1000f011 )
K7AntiVirusTrojan ( f1000f011 )
VirITTrojan.Win32.Pakes.FRZ
CyrenW32/Qakbot.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Delf.POH
APEXMalicious
Paloaltogeneric.ml
KasperskyPacked.Win32.Krap.hm
BitDefenderGen:Variant.Ransom.4
NANO-AntivirusTrojan.Win32.Krap.ccmtk
AvastFileRepMalware
RisingWorm.Conficker!8.278 (RDMK:cmRtazpXrXinxBE6ZTdLuJSiXqv7)
Ad-AwareGen:Variant.Ransom.4
EmsisoftGen:Variant.Ransom.4 (B)
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.MulDrop3.41133
ZillyaDownloader.Delf.Win32.58384
TrendMicroBKDR_QAKBOT.SMC
McAfee-GW-EditionPWS-Zbot.gen.aum
SophosMal/Generic-S + Mal/Zbot-U
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Ransom.4
JiangminTrojanDownloader.Agent.cdbh
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Ransom.4
ViRobotTrojan.Win32.A.Downloader.49664.DL
ZoneAlarmPacked.Win32.Krap.hm
MicrosoftTrojan:Win32/Oficla.T
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R414006
BitDefenderThetaAI:Packer.211899791F
ALYacGen:Variant.Ransom.4
MAXmalware (ai score=100)
TrendMicro-HouseCallBKDR_QAKBOT.SMC
TencentWin32.Packed.Krap.Dxmg
YandexTrojan.GenAsa!OI6J+J7ijYc
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1382627.susgen
FortinetW32/Agent.DTII!tr.dldr
AVGFileRepMalware
Cybereasonmalicious.242bac
PandaTrj/Krapack.gen

How to remove Trojan:Win32/Oficla.T?

Trojan:Win32/Oficla.T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment