Backdoor

Backdoor.Win32.Gulpix.vho removal instruction

Malware Removal

The Backdoor.Win32.Gulpix.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Gulpix.vho virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
cdn.vy68.com
AndyHarrison-PC
brickola.cn
wpad
js.26ji.cn
apps.game.qq.com
a.tomx.xyz
map.baidu.com
z8.cnzz.com

How to determine Backdoor.Win32.Gulpix.vho?


File Info:

crc32: F7E5F68E
md5: a02f3e8c1a13abbf72c214d4260dc621
name: qwertyuiop009.exe
sha1: faf593f6496a7609518acbb1fedd7d21a8ada052
sha256: 6a02d844c9b64c1df1435a6d51807ad0396d587daa2ddf114353f05c0ce9ace7
sha512: 0cfcfe98c793671c21f321dd8f4959c2cf855b1f452ee910815ff62bdac76f019712519f65b93035b2050a6110520767a60d67d4fefddefd587005f560da6065
ssdeep: 6144:zRmi340K2FCwmrNlEw6IcRTmfTIk8Vd0ReC5iYVxtgOG6vu8xA:zZ340K0CwwJRuGIkaIedotg38x
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 19, 10, 12, 2
ProductVersion: 19, 10, 12, 2
Translation: 0x0804 0x04b0

Backdoor.Win32.Gulpix.vho also known as:

MicroWorld-eScanGen:Variant.Graftor.494706
FireEyeGeneric.mg.a02f3e8c1a13abbf
Qihoo-360Generic/HEUR/QVM17.0.E79B.Malware.Gen
McAfeeArtemis!A02F3E8C1A13
CylanceUnsafe
VIPRETrojan-Spy.Win32.Zbot.gen (v)
BitDefenderGen:Variant.Graftor.494706
Cybereasonmalicious.c1a13a
F-ProtW32/Graftor.FI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Graftor.494706
KasperskyHEUR:Backdoor.Win32.Gulpix.vho
AlibabaBackdoor:Win32/Gulpix.a5ff15ab
NANO-AntivirusTrojan.Win32.Graftor.gsdvwq
Ad-AwareGen:Variant.Graftor.494706
SophosMal/Behav-010
F-SecureHeuristic.HEUR/AGEN.1103265
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Gupboot.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.494706 (B)
CyrenW32/Graftor.FI.gen!Eldorado
AviraHEUR/AGEN.1103265
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Graftor.D78C72
ZoneAlarmHEUR:Backdoor.Win32.Gulpix.vho
AhnLab-V3Trojan/Win32.Agent.C3143770
Acronissuspicious
BitDefenderThetaAI:Packer.DE0B93221F
VBA32BScope.Trojan.Tiggre
ESET-NOD32a variant of Win32/Agent.ZJL
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazqD5TvaMKIwdOXUDFvMaY8M)
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.Gulpix.vho?

Backdoor.Win32.Gulpix.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment