Backdoor

Backdoor.Linux.Gafgyt.1 information

Malware Removal

The Backdoor.Linux.Gafgyt.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Linux.Gafgyt.1 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Linux.Gafgyt.1?


File Info:

crc32: B7665CA4
md5: 07ce1d3c5fbd3739423233f1172240dc
name: upload_file
sha1: 12daaf299ae38b6fa7c4e5091c95bad1f2f51d93
sha256: 4b572c6d2e1d07012ac3701b75b693bde555ab52f24083d21dc43ea3e1b39ee8
sha512: 458965649ade7843229ddc8582c9cce4f6875aa8313f5c481e9740f08aae2f3503714e622c5bba941142ecb132d73b8f2ad063d5235745ec9d1c5c2d78a84e69
ssdeep: 3072:A+6NBB/WfPLbVjEWCVFNyCFo3WU+E1p54o3BEmTo0dVJ4VsKb:A+6nQfPLbVjEWCVMWfE1Ao3BEmTo0dVa
type: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped

Version Info:

0: [No Data]

Backdoor.Linux.Gafgyt.1 also known as:

ClamAVUnix.Trojan.Gafgyt-6981154-0
FireEyeGen:Variant.Backdoor.Linux.Gafgyt.1
McAfeeLinux/Gafgyt.h
SangforMalware
BitDefenderThetaGen:NN.Mirai.34196
CyrenELF/Gafgyt.D.gen!Camelot
SymantecTrojan.Gen.NPE
TrendMicro-HouseCallBackdoor.Linux.BASHLITE.SMJC
AvastELF:DDoS-Y [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Backdoor.Linux.Gafgyt.af
BitDefenderGen:Variant.Backdoor.Linux.Gafgyt.1
NANO-AntivirusTrojan.Elf32.Gafgyt.eikqfj
AegisLabTrojan.Linux.Gafgyt.m!c
MicroWorld-eScanGen:Variant.Backdoor.Linux.Gafgyt.1
TencentTrojan.Linux.Gafgyt.hb
Ad-AwareGen:Variant.Backdoor.Linux.Gafgyt.1
Comodo.UnclassifiedMalware@0
F-SecureMalware.LINUX/Gafgyt.gafyd
DrWebLinux.BackDoor.Fgt.44
ZillyaBackdoor.Gafgyt.Linux.56575
TrendMicroBackdoor.Linux.BASHLITE.SMJC
SophosLinux/DDoS-BI
IkarusTrojan.Linux.Generic
GDataLinux.Trojan.Gafgyt.B
JiangminBackdoor.Linux.rgd
AviraLINUX/Gafgyt.gafyd
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Linux.Gafgyt.af
MicrosoftDDoS:Linux/Lightaidra
ArcabitTrojan.Backdoor.Linux.Gafgyt.1
ZoneAlarmHEUR:Backdoor.Linux.Gafgyt.af
Avast-MobileELF:DDoS-S [Trj]
AhnLab-V3Linux/Gafgyt.90112.C
ALYacGen:Variant.Backdoor.Linux.Gafgyt.1
ESET-NOD32a variant of Linux/Gafgyt.C
RisingBackdoor.Gafgyt/Linux!1.A512 (CLASSIC)
SentinelOneDFI – Malicious ELF
FortinetELF/Gafgyt.BJ!tr
AVGELF:DDoS-Y [Trj]
Qihoo-360Linux/Backdoor.746

How to remove Backdoor.Linux.Gafgyt.1?

Backdoor.Linux.Gafgyt.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment