Backdoor

What is “Backdoor:Win32/Gaobot”?

Malware Removal

The Backdoor:Win32/Gaobot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Gaobot virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Gaobot?


File Info:

name: 5F4D46FB3FD4C66346B5.mlw
path: /opt/CAPEv2/storage/binaries/cfeaaef35a828ab7dc9e512a76ba0a474906215976604c5418a62ca26203c916
crc32: 2D5FCF10
md5: 5f4d46fb3fd4c66346b505433f76fd89
sha1: c17ce55963d75a21098c43d264ff5f6543336fd6
sha256: cfeaaef35a828ab7dc9e512a76ba0a474906215976604c5418a62ca26203c916
sha512: 1b142928e5d3f28234a5af2e4fd3fd1420b937cbf35d3c0e319182980c3ed1758104c4770abf3991b776788d7f87e3197932a4febd06ca80d7a0e4f2031738ab
ssdeep: 768:XthuQO6qktDv9tEvm4qR78nXPeuzYiX8dlM:XtAeB9tEvmZ7m/eu6lM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13A137D23BCE18533C9D351B101F08F2AAF7FB5621672A4539720AD4A2D719E19E3B357
sha3_384: dfc4cc90c986173729913feb853f2b416888d62db94db53846fc94dd8f324c1d01246774ed8251de0a65ee19d3dc5b06
ep_bytes: 558bec6aff680071400068502c400064
timestamp: 2003-10-24 18:27:28

Version Info:

0: [No Data]

Backdoor:Win32/Gaobot also known as:

DrWebWin32.HLLW.Agobot.3
MicroWorld-eScanBackdoor.Agobot.3.z
FireEyeBackdoor.Agobot.3.z
McAfeeW32/Gaobot.d.gen
CylanceUnsafe
ZillyaBackdoor.Agobot.Win32.743
SangforWorm.Win32.Agobot.45056
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Agobot.f6f3c507
K7GWBackdoor ( 000009b31 )
K7AntiVirusBackdoor ( 000009b31 )
CyrenW32/Agobot.OKEZ-8176
SymantecBackdoor.Gaobot
ESET-NOD32Win32/Agobot.3.BJ
TrendMicro-HouseCallBKDR_GAOBOT.B
ClamAVWin.Worm.Gaobot-120
KasperskyBackdoor.Win32.Agobot.z
BitDefenderBackdoor.Agobot.3.z
NANO-AntivirusTrojan.Win32.Agobot.daya
AvastWin32:GaoBot-WB [Wrm]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareBackdoor.Agobot.3.z
SophosMal/Generic-R + W32/Agobot-DT
ComodoBackdoor.Win32.Agobot.3.BJ@390z
VIPREBackdoor.Gaobot
TrendMicroBKDR_GAOBOT.B
McAfee-GW-EditionW32/Gaobot.d.gen
EmsisoftBackdoor.Agobot.3.z (B)
IkarusBackdoor.Win32.Agobot
JiangminBackdoor/Agobot.3.z
AviraWORM/AgoBot.45056
Antiy-AVLTrojan/Generic.ASMalwS.1F50C
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftBackdoor:Win32/Gaobot
ViRobotBackdoor.Win32.S.Agobot.45056
GDataBackdoor.Agobot.3.z
AhnLab-V3Worm/Win32.IRCBot.R122142
VBA32Backdoor.Agobot
ALYacBackdoor.Agobot.3.z
TACHYONBackdoor/W32.AgoBot.45056
MalwarebytesMalware.AI.4154456298
RisingBackdoor.Agobot.3.c (CLASSIC)
YandexBackdoor.Agobot.Gen.12
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.158173.susgen
FortinetW32/Agobot.Z!tr
WebrootW32.Trojan.Agobot
AVGWin32:GaoBot-WB [Wrm]
PandaBck/Sdbot.BPA

How to remove Backdoor:Win32/Gaobot?

Backdoor:Win32/Gaobot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment