Backdoor

How to remove “Backdoor.Linux.Gafgyt.az”?

Malware Removal

The Backdoor.Linux.Gafgyt.az is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Linux.Gafgyt.az virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Linux.Gafgyt.az?


File Info:

crc32: E75BD8D5
md5: 880fb59b4cc5500b68490146ce015bff
name: upload_file
sha1: 7e5851d90c78c1bc547b1258068953273abae8fd
sha256: 29e81c13eeb87517d9269bc4f8dcb0796eb2532d3b0ff30a7796619d828cd0a9
sha512: 4affd3578ffc048b10ab0100643f18af3a76477c2ca1c975dc4646c17d82bf9bdacc8d1a5ab76fc9c34a116250f0bb9e8918f74a9b98178fe58faf6b7658f43e
ssdeep: 1536:k9ufYH/fuFDUW6DpifWyMJ3679l5MY+rr+h/cmbJpVoBjZ4fZkP:W+YH/fuFDj6AOlgjcmtpVoBF4fZkP
type: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped

Version Info:

0: [No Data]

Backdoor.Linux.Gafgyt.az also known as:

ClamAVUnix.Trojan.Mirai-5607483-0
FireEyeGen:Variant.Trojan.Linux.Gafgyt.5
McAfeeLinux/Gafgyt.h
SangforMalware
TrendMicroBackdoor.Linux.BASHLITE.SMJC2
SymantecLinux.Lightaidra
TrendMicro-HouseCallBackdoor.Linux.BASHLITE.SMJC2
AvastELF:DDoS-Y [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Backdoor.Linux.Gafgyt.az
BitDefenderGen:Variant.Trojan.Linux.Gafgyt.5
MicroWorld-eScanGen:Variant.Trojan.Linux.Gafgyt.5
Ad-AwareGen:Variant.Trojan.Linux.Gafgyt.5
SophosMal/Generic-S
ComodoMalware@#1rzj7sfz7vtji
F-SecureMalware.LINUX/Gafgyt.nvhbm
DrWebLinux.BackDoor.Fgt.1440
McAfee-GW-EditionLinux/Gafgyt.h
EmsisoftGen:Variant.Trojan.Linux.Gafgyt.5 (B)
SentinelOneDFI – Malicious ELF
GDataLinux.Trojan.Gafgyt.B
JiangminBackdoor.Linux.cxuu
AviraLINUX/Gafgyt.nvhbm
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Linux.Gafgyt.az
MicrosoftTrojan:Win32/Ymacco.AB29
ArcabitTrojan.Trojan.Linux.Gafgyt.5
ZoneAlarmHEUR:Backdoor.Linux.Gafgyt.az
Avast-MobileELF:DDoS-S [Trj]
AhnLab-V3Linux/Gafgyt.Gen25
ALYacGen:Variant.Trojan.Linux.Gafgyt.5
ESET-NOD32a variant of Linux/Gafgyt.ANW
RisingBackdoor.Gafgyt!8.56E (TFE:14:qGwqKCQdHMC)
IkarusTrojan.Linux.Generic
FortinetELF/Gafgyt.BJ!tr
BitDefenderThetaGen:NN.Mirai.34282
AVGELF:DDoS-Y [Trj]
Qihoo-360Linux/Backdoor.e06

How to remove Backdoor.Linux.Gafgyt.az?

Backdoor.Linux.Gafgyt.az removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment