Backdoor

How to remove “Backdoor.Linux.Gafgyt.ba”?

Malware Removal

The Backdoor.Linux.Gafgyt.ba is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Linux.Gafgyt.ba virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Linux.Gafgyt.ba?


File Info:

crc32: 16AA6094
md5: f70175ee32fec131af8358385f7bb17f
name: upload_file
sha1: 8e1983a7b974c3439a232c0de434c0fe96f07eda
sha256: b5882eda8fff518b080b8f7a80ea16ba570905b2c5399d6118c262da5af1eab6
sha512: 7b42a506267a24b4fd9d40ff6fca9cdd0670a6fc3c33fa94e4df52c0cb597a40590501fbde55681dafa0553e4ec5baf9d03c966e4ea340efe493ed194faba06c
ssdeep: 3072:SuHfTSRoMzJBR4fJaQaxY04/1H1NfD5TleqM55uVzX5eVAM3cml7qX1XmvUC/LrH:dNDYY39VtD5Ze/5UHlM3cml7qFXmvUCn
type: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped

Version Info:

0: [No Data]

Backdoor.Linux.Gafgyt.ba also known as:

FireEyeGen:Variant.Trojan.Linux.Gafgyt.5
ALYacGen:Variant.Trojan.Linux.Gafgyt.5
SangforMalware
InvinceaLinux/DDoS-CIA
BitDefenderThetaGen:NN.Mirai.34254
CyrenE64/Gafgyt.C.gen!Camelot
TrendMicro-HouseCallBackdoor.Linux.GAFGYT.SMMR1
ClamAVUnix.Trojan.Mirai-1
KasperskyHEUR:Backdoor.Linux.Gafgyt.ba
BitDefenderGen:Variant.Trojan.Linux.Gafgyt.5
MicroWorld-eScanGen:Variant.Trojan.Linux.Gafgyt.5
RisingBackdoor.Mirai/Linux!1.BAF6 (CLASSIC)
Ad-AwareGen:Variant.Trojan.Linux.Gafgyt.5
SophosLinux/DDoS-CIA
DrWebLinux.BackDoor.Fgt.3829
TrendMicroBackdoor.Linux.GAFGYT.SMMR1
McAfee-GW-EditionLinux/Gafgyt!F70175EE32FE
EmsisoftGen:Variant.Trojan.Linux.Gafgyt.5 (B)
SentinelOneDFI – Malicious ELF
GDataLinux.Trojan.Gafgyt.B
MAXmalware (ai score=87)
Antiy-AVLTrojan[Backdoor]/Linux.Gafgyt.ba
MicrosoftBackdoor:Linux/Mirai.bc!MTB
ArcabitTrojan.Trojan.Linux.Gafgyt.5
ZoneAlarmHEUR:Backdoor.Linux.Gafgyt.ba
Avast-MobileELF:Mirai-UM [Trj]
AhnLab-V3Linux/Mirai.Gen
ESET-NOD32a variant of Linux/Mirai.B
IkarusTrojan.Linux.Gafgyt
FortinetELF/Gafgyt.BI
AVGELF:Gafgyt-DZ [Trj]

How to remove Backdoor.Linux.Gafgyt.ba?

Backdoor.Linux.Gafgyt.ba removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment