Rootkit

Should I remove “Dropped:Generic.Rootkit.Gooser.011C73CD”?

Malware Removal

The Dropped:Generic.Rootkit.Gooser.011C73CD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Rootkit.Gooser.011C73CD virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Dropped:Generic.Rootkit.Gooser.011C73CD?


File Info:

name: 0C5D5F2D0DD70D46E181.mlw
path: /opt/CAPEv2/storage/binaries/4f99354ba9866e65d87fb397d0c7468bb060aa912fa207d4f52f287564ff1e67
crc32: B0139038
md5: 0c5d5f2d0dd70d46e1812e4a25c03864
sha1: accd8d24c30918e2d244bdbd6510f615e39a3dde
sha256: 4f99354ba9866e65d87fb397d0c7468bb060aa912fa207d4f52f287564ff1e67
sha512: f49076c251755e75a5fa34b9474decfbcb27fc4ac33475a8bb3b012a7fab73c0d60a4b0caaba535116648b866ca1bf0b135d3d458486872e8e36ce3acce51433
ssdeep: 768:qpvFrkRmnfYNSxE+WpJhUjkeDRmMK2ftkqt/n4X0Zn5:qjgQfYA2+cJqjvNt+W/1p5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133E2E0027BE650A5F885C2700A61D67FE74DFCA48FB2C7E90E4EDB8E1E6116D19350A3
sha3_384: b4ac8c3720d7eebfa21e1d6cb8d3363efbaa4006a2dfdd3d2651ed46981383015b6fb26febd91ff06f8aeb4cf5ff529b
ep_bytes: 60be00f040008dbe0020ffff5783cdff
timestamp: 2008-12-09 14:13:30

Version Info:

Comments:
CompanyName:
FileDescription:
FileVersion: 1, 0, 0, 1
InternalName:
LegalCopyright: Copyright ? 2008
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Dropped:Generic.Rootkit.Gooser.011C73CD also known as:

LionicTrojan.Win32.Agent.lgJD
MicroWorld-eScanDropped:Generic.Rootkit.Gooser.011C73CD
ClamAVWin.Downloader.61873-1
FireEyeGeneric.mg.0c5d5f2d0dd70d46
CAT-QuickHealTrojan.Dogrobot.J.mue
McAfeeGenericRXAA-AA!0C5D5F2D0DD7
CylanceUnsafe
VIPREDropped:Generic.Rootkit.Gooser.011C73CD
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0005d28d1 )
AlibabaBackdoor:Win32/Gofot.85df3496
K7GWTrojan ( 0005d28d1 )
Cybereasonmalicious.d0dd70
BaiduWin32.Trojan.Agent.aao
VirITTrojan.Win32.Agent3.LFY
CyrenW32/S-5c22485d!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.ONB
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Gofot.cyp
BitDefenderDropped:Generic.Rootkit.Gooser.011C73CD
NANO-AntivirusTrojan.Win32.Agent.qbou
AvastFileRepMalware [Trj]
TencentWin32.Trojan-Downloader.Oader.Oqil
Ad-AwareDropped:Generic.Rootkit.Gooser.011C73CD
SophosML/PE-A + Mal/Behav-009
ComodoTrojWare.Win32.PSW.OnLineGames.~KCT@1hzq0
DrWebTrojan.DownLoader5.28948
ZillyaTrojan.Agent.Win32.25165
TrendMicroTROJ_DLOADR.ERC
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
Trapminemalicious.moderate.ml.score
EmsisoftDropped:Generic.Rootkit.Gooser.011C73CD (B)
IkarusTrojan.Win32.AntiAV
GDataDropped:Generic.Rootkit.Gooser.011C73CD
JiangminTrojanDownloader.Agent.anuz
WebrootW32.Farfli.Gen
AviraTR/Agent.gnyo
Antiy-AVLTrojan/Generic.ASMalwS.2D
ArcabitGeneric.Rootkit.Gooser.011C73CD
ViRobotTrojan.Win32.Agent.33280.AF
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R1326
VBA32BScope.TrojanDownloader.Agent
ALYacDropped:Generic.Rootkit.Gooser.011C73CD
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_DLOADR.ERC
RisingBackdoor.Farfli!8.B4 (TFE:5:Aj3Gs30OVH)
YandexTrojan.GenAsa!Uj8n+CfftEw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Runner.BV!tr
BitDefenderThetaAI:Packer.98B24AF01F
AVGFileRepMalware [Trj]
PandaTrj/Downloader.UZB
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Dropped:Generic.Rootkit.Gooser.011C73CD?

Dropped:Generic.Rootkit.Gooser.011C73CD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment