Backdoor

About “Backdoor.Gozi” infection

Malware Removal

The Backdoor.Gozi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Gozi virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Gozi?


File Info:

crc32: F6E6A4CE
md5: 691bb0fff3ce5103833444d388795bb0
name: 691BB0FFF3CE5103833444D388795BB0.mlw
sha1: aa35da6f364561051eacbc7aba9c54b84b31ae68
sha256: b51701fcf002cffcc361a7e111aff2a19fd98e591df61d1ec93c641ce5fa1cb1
sha512: 3f55e937955c4019937b0e922a73ab05b9d143494dc7356f72fd66658e60db1ec59bd76d96e160a4070ffd500839c649f19a8af030a72e3118c30e36b6e75f7f
ssdeep: 6144:9wHysGizZaG7GqfHeY8mHhnL28QvgKxgDzUearh2TqvapZl8UMlu:mGUQq38vLdiUeS9vaHJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Backdoor.Gozi also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0050a7671 )
LionicTrojan.NSIS.Inject.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Gozi.85
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A
ALYacTrojan.Ransom.cryptolocker
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.70226
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Enestaller.e22e9bf6
K7GWTrojan ( 0050a7671 )
Cybereasonmalicious.ff3ce5
CyrenW32/Trojan.TDNS-2700
SymantecRansom.Cerber
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.5975602
NANO-AntivirusTrojan.Win32.Inject.entcdw
MicroWorld-eScanTrojan.GenericKD.5975602
TencentNsis.Trojan.Inject.Wnmp
Ad-AwareTrojan.GenericKD.5975602
SophosMal/Generic-R + Mal/Cerber-Z
ComodoMalware@#1ghzt7mihlxj4
BitDefenderThetaGen:NN.ZedlaF.34790.bS8@aOOylGoi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-Cerber
FireEyeTrojan.GenericKD.5975602
EmsisoftTrojan.Injector (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1111189
KingsoftWin32.Troj.Inject.WN.(kcloud)
MicrosoftRansom:Win32/Enestaller.AE!rsm
ArcabitTrojan.Generic.D5B2E32
SUPERAntiSpywareRansom.CryptoLocker/Variant
GDataTrojan.GenericKD.5975602
AhnLab-V3Trojan/Win32.Cerber.R197930
McAfeeRansomware-Cerber
MAXmalware (ai score=100)
VBA32Backdoor.Gozi
PandaTrj/RansomCrypt.E
TrendMicro-HouseCallRansom_CRYPTLOCK.QAF
YandexTrojan.Inject!6qWzO2to5y8
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DNRA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Inject.HyoDEpsA

How to remove Backdoor.Gozi?

Backdoor.Gozi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment