Backdoor

Backdoor:Win32/Gobot.A removal instruction

Malware Removal

The Backdoor:Win32/Gobot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Gobot.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Gobot.A?


File Info:

name: 243640AAF2931C065A2C.mlw
path: /opt/CAPEv2/storage/binaries/8d3edcb81817abdc1c8b3836985d0e72458a896139ff5975f6ff61ed3731ba4f
crc32: 05E14B18
md5: 243640aaf2931c065a2c259150a80111
sha1: f6c1e73c3f324961c585bc54893f3fc1935ed573
sha256: 8d3edcb81817abdc1c8b3836985d0e72458a896139ff5975f6ff61ed3731ba4f
sha512: 17f2f23f438ce312e64bdbfee293eb11ec34a90722b046519d9d6b59129ae6152c36a19c72af91245231b85bc5e4b8bdc1d01e2edbc069cc7934aae259bf9a78
ssdeep: 768:5w1md/3gGa+R3v+JNe+mP4jB/4ZFTMb1iv6w00uMgAyuRy4N7:55qGlRGNjmP4jBA3MbUv1/t/y8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C23E11FF309C9E1C812E8BC6E3F65B8DA5008D466D255BE48B0B93BEF692D1DDD1422
sha3_384: 5695eaf739b84c701a5e0949f2dcac4a9b62a69984dc11283fa5b4b551cc79a710f5b7ab1d3676551db648e4992d3ed1
ep_bytes: 9061be003041008dbe00e0feffc787f8
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Gobot.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gobot.lfDt
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Malware.GLPV!dld!.7625B0CB
ClamAVWin.Trojan.Gobot-1
FireEyeGeneric.mg.243640aaf2931c06
CAT-QuickHealBackdoor.Gobot
ALYacDeepScan:Generic.Malware.GLPV!dld!.7625B0CB
Cylanceunsafe
ZillyaBackdoor.Gobot.Win32.16
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004d126e1 )
AlibabaMalware:Win32/km_2804ad.None
K7GWTrojan ( 004d126e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.652CC0211F
VirITTrojan.Win32.BackDoor.GOBOT
CyrenW32/Gobot.AHAX-4275
SymantecW32.Gobot.A
ESET-NOD32Win32/Gobot.R
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Gobot.gen
BitDefenderDeepScan:Generic.Malware.GLPV!dld!.7625B0CB
NANO-AntivirusTrojan.Win32.Gobot.hhoo
SUPERAntiSpywareTrojan.Agent/Gen-Gobot
AvastWin32:Gobot-B [Trj]
TencentMalware.Win32.Gencirc.10b10bed
EmsisoftDeepScan:Generic.Malware.GLPV!dld!.7625B0CB (B)
BaiduWin32.Backdoor.Gobot.b
F-SecureWorm.WORM/Doomber.D
DrWebWin32.HLLW.Ghostbot
VIPREDeepScan:Generic.Malware.GLPV!dld!.7625B0CB
TrendMicroWORM_GOBOT.G
McAfee-GW-EditionBehavesLike.Win32.PolyPatch.pc
Trapminemalicious.high.ml.score
SophosW32/Gobot-J
SentinelOneStatic AI – Malicious PE
GDataDeepScan:Generic.Malware.GLPV!dld!.7625B0CB
JiangminTrojanDownloader.Delf.pgr
AviraWORM/Doomber.D
Antiy-AVLTrojan[Backdoor]/Win32.Gobot
XcitiumBackdoor.Win32.Gobot.R@3495
ArcabitDeepScan:Generic.Malware.GLPV!dld!.7625B0CB
ViRobotBackdoor.Win32.Gobot.47073
ZoneAlarmBackdoor.Win32.Gobot.gen
MicrosoftBackdoor:Win32/Gobot.A
GoogleDetected
AhnLab-V3Worm/Win32.IRCBot.R29095
McAfeeArtemis!243640AAF293
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Gobot
MalwarebytesGeneric.Malware.AI.DDS
PandaBck/Gotob.AA
TrendMicro-HouseCallWORM_GOBOT.G
RisingTrojan.DL.Win32.Delf.bm (CLOUD)
YandexTrojan.GenAsa!ER9GsyLwXhc
IkarusBackdoor.Win32.Gobot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gobot.D!worm
AVGWin32:Gobot-B [Trj]
Cybereasonmalicious.af2931
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Gobot.A?

Backdoor:Win32/Gobot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment