Trojan

UDS:Trojan-Downloader.Win32.OffLoader removal

Malware Removal

The UDS:Trojan-Downloader.Win32.OffLoader is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Downloader.Win32.OffLoader virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine UDS:Trojan-Downloader.Win32.OffLoader?


File Info:

name: BE2362C64F2EC45DBEF9.mlw
path: /opt/CAPEv2/storage/binaries/4f76bdf76490c5be1f7d646e04c88d0dd1ea34f2c36cddc8849d1a6d866df67c
crc32: A9FBC7C8
md5: be2362c64f2ec45dbef977bd1cc3c4c6
sha1: 3854a0f82f77d4939627fdba88d3dc45262d6ff2
sha256: 4f76bdf76490c5be1f7d646e04c88d0dd1ea34f2c36cddc8849d1a6d866df67c
sha512: 2ad90ad338e8b4e3e798b7dc9a56854625bff134a07c165e7fd52fa3db0504e5f48a378da374e57c8b922dda490995c627d08d55798beb4942695f6c2316025d
ssdeep: 24576:N4nXubIQGyxbPV0db26Bh+vogz2dbFFv0S6dS/01icZOEOR5QvZ0:Nqe3f6T+DidXvh6dS/04OOR5QvZ0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D775BF3FB268A53EC4AA0B3245B39360997BBB61B81A8C1F57F0490DCF664701F3B655
sha3_384: 587ac45a6597a98dfe74ed36de7205803d0c3cc81d6791209c26bf6c3251c2bbb3a548e6622ed3dd8e43cb7b017a3cfc
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Justice work in spare time Final By Quiet Northern Lands.exe
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Justice work in spare time Final By Quiet Northern Lands.exe
ProductVersion: 1.0
Translation: 0x0000 0x04b0

UDS:Trojan-Downloader.Win32.OffLoader also known as:

CrowdStrikewin/grayware_confidence_60% (W)
CyrenW32/Agent.FLZ.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GPE
CynetMalicious (score: 99)
KasperskyUDS:Trojan-Downloader.Win32.OffLoader
AvastFileRepMalware [Misc]
F-SecureTrojan.TR/Downloader.Gen
McAfee-GW-EditionBehavesLike.Win32.DLAssistant.tc
Trapminesuspicious.low.ml.score
AviraTR/Downloader.Gen
ZoneAlarmUDS:Trojan-Downloader.Win32.OffLoader
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
McAfeeArtemis!BE2362C64F2E
Cylanceunsafe
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove UDS:Trojan-Downloader.Win32.OffLoader?

UDS:Trojan-Downloader.Win32.OffLoader removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment