Backdoor

What is “Backdoor:Win32/Ghole!dha”?

Malware Removal

The Backdoor:Win32/Ghole!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Ghole!dha virus can do?

  • Unconventionial language used in binary resources: Spanish (Argentina)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Ghole!dha?


File Info:

name: 14F2E86F11114C083856.mlw
path: /opt/CAPEv2/storage/binaries/7e48f22f7cc03f1b14fb2069bf55f0826d314850eeeca04553dcd1679119d7b4
crc32: 4C3315A9
md5: 14f2e86f11114c083856c92095d79256
sha1: 7fef48e1303e40110798dfec929ad88f1ad4fbd8
sha256: 7e48f22f7cc03f1b14fb2069bf55f0826d314850eeeca04553dcd1679119d7b4
sha512: 8b1e248bec3827812a6e097d0722a6590dcf789c7fb3be92c206369de1d879d3400b7fa81e01032943e5f4637565e3858cb648b6a0a5c42eef01331eb88d9233
ssdeep: 768:7cUqTbtWoUzE/h8DWi9E/q43X1jCqVOEOgbtdzZU9qZU94:7Sb4xzE/U9Ey4VLWetdzpT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155543A01390248EDE309CB308771A7B00AAB7C2A29B1F07EFB6879255D71186D577DEE
sha3_384: 5f5ef7a14b6a83df9bf33d2f15493759fdec5a088f3474580b0a57af550f7afad71fa15c440e8b5a4a1d1b40919b9dc6
ep_bytes: e8ae170000e917feffff558bec81ec28
timestamp: 2012-11-22 15:59:05

Version Info:

0: [No Data]

Backdoor:Win32/Ghole!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Woolerg.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.102878
ClamAVWin.Malware.Zusy-9963620-0
FireEyeGeneric.mg.14f2e86f11114c08
CAT-QuickHealTrojan.GholeeRI.S21443535
SkyhighBehavesLike.Win32.Corrupt.dz
McAfeeTrojan-FCUP!14F2E86F1111
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Wedex.Win32.5
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b483e1 )
BitDefenderGen:Variant.Midie.102878
K7GWTrojan ( 004b483e1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITBackdoor.Win32.Poison.WZO
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Wedex.AA
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Gholee.gen
AlibabaBackdoor:Win32/Woolerg.243640b6
NANO-AntivirusTrojan.Win32.Poison.cxuqnz
TencentMalware.Win32.Gencirc.10b864d9
EmsisoftGen:Variant.Midie.102878 (B)
F-SecureTrojan.TR/Zusy.3718.13
DrWebBackDoor.Poison.15536
VIPREGen:Variant.Midie.102878
TrendMicroBKDR_GHOLE.A
SophosTroj/Ghole-A
IkarusTrojan.Win32.Pincav
GDataGen:Variant.Midie.102878
JiangminTrojan/Generic.aycht
GoogleDetected
AviraTR/Zusy.3718.13
Antiy-AVLTrojan[APT]/Win32.Apt35
KingsoftWin32.Trojan.Gholee.gen
XcitiumMalware@#1js88h9iq6csv
ArcabitTrojan.Midie.D191DE
ZoneAlarmHEUR:Trojan.Win32.Gholee.gen
MicrosoftBackdoor:Win32/Ghole!dha
VaristW32/WoolFish.A.gen!Eldorado
AhnLab-V3Trojan/Win32.Injector.R138611
VBA32Trojan.Woolerg
ALYacGen:Variant.Midie.102878
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_GHOLE.A
RisingBackdoor.Ghole!8.6975 (TFE:5:ayRW3mJTAOS)
YandexTrojan.GenAsa!//VjEvhpJWQ
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Generic!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]

How to remove Backdoor:Win32/Ghole!dha?

Backdoor:Win32/Ghole!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment