Backdoor

Backdoor.Gwboy.A removal

Malware Removal

The Backdoor.Gwboy.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Gwboy.A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.Gwboy.A?


File Info:

name: C767B23A9CA46EB97E40.mlw
path: /opt/CAPEv2/storage/binaries/498cc797cb974b8bc357d6647ae140494d2352e83811c3804e2a219d9af322a3
crc32: 19DF0D70
md5: c767b23a9ca46eb97e40815cabca181e
sha1: 3247723defcb64a43e4f857283cf3e50051090cf
sha256: 498cc797cb974b8bc357d6647ae140494d2352e83811c3804e2a219d9af322a3
sha512: ca69a4e0ac46611e404c7577d6052f25b1b876b6930208626f5abd88d8c6910e7a388da39065c9c743ec7404621496f90df6db650e515478e4add56928b3fd2d
ssdeep: 3072:noN0pvQWLP4kVC2Ir8Xh4wCh9XczMuIGNH3JQ:tv5VArO4wChBSMuIGNe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBC301539FC19CF3E0C4E5F058765268AB3BA6703D278663A8C88DCC9E5F164B94D227
sha3_384: e2e2166f2e662e84636e1bb76707350e04699c56da470aef99c9ada2fb8e3953ee667e80eeffbaed0f2ffd654edb9ccc
ep_bytes: 558bec83c4ec53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Gwboy.A also known as:

tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Gwboy.A
ALYacBackdoor.Gwboy.A
CylanceUnsafe
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderBackdoor.Gwboy.A
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.a9ca46
ArcabitBackdoor.Gwboy.A
CyrenW32/Backdoor.EGPX-3485
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/GWBoy
APEXMalicious
KasperskyBackdoor.Win32.GWBoy
NANO-AntivirusTrojan.Win32.GWBoy.csozfw
Ad-AwareBackdoor.Gwboy.A
EmsisoftBackdoor.Gwboy.A (B)
ComodoBackdoor.Win32.GWBoy@3241
DrWebBackDoor.GWBoy.91
ZillyaBackdoor.GWBoy.Win32.8
TrendMicroTROJ_GEN.R03BC0DDU22
McAfee-GW-EditionBehavesLike.Win32.Sytro.cc
FireEyeGeneric.mg.c767b23a9ca46eb9
SophosML/PE-A
IkarusTrojan-Spy.Win32.GWGhost.H
JiangminBackdoor/GWBoy.Dropper
AviraBDS/GWBoy.5
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataBackdoor.Gwboy.A
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win.GWGhost.C5092171
Acronissuspicious
McAfeeBackDoor-ASV
MAXmalware (ai score=84)
VBA32Backdoor.GWBoy
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DDU22
RisingTrojan.Generic@AI.94 (RDMK:cmRtazpmEulBD2vQozr3bRI/uZ4/)
YandexTrojan.GenAsa!XPVGrK5kzB4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.9670.susgen
FortinetW32/GWBoy.A!tr.bdr
BitDefenderThetaGen:NN.ZelphiF.34638.hSZ@a0PqH2p
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor.Gwboy.A?

Backdoor.Gwboy.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment