Malware

Linux/Gafgyt.AMV removal tips

Malware Removal

The Linux/Gafgyt.AMV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Linux/Gafgyt.AMV virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Linux/Gafgyt.AMV?


File Info:

crc32: 638947C0
md5: 6894b023c4fd087a4b45dd352de113f1
name: upload_file
sha1: cb0a65ba5977884c163939b693a4398e5e021265
sha256: 95291138c83c58fdd0f58544af039859072ded53614dc7f23c546342443a544f
sha512: c5b7d91e535744d040b83c169f3cf12d346e01e6088ab5e27563fd008e59105d3c19a627743a0406117c6fd876327979f59d9f6ed8fc11b25a30d1bac8602364
ssdeep: 1536:WHAcq3fJONw1Ej5OPqzKWQC8jIOlfPUEikuIr5htm:6qMNw1EVie98jIOFPUEuM5htm
type: ERROR: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linkederror reading (Invalid argument)

Version Info:

0: [No Data]

Linux/Gafgyt.AMV also known as:

SangforMalware
ESET-NOD32a variant of Linux/Gafgyt.AMV
AvastELF:Mirai-TX [Trj]
ClamAVUnix.Proxy.Mirai-7844054-0
KasperskyHEUR:Backdoor.Linux.Gafgyt.bl
RisingBackdoor.Gafgyt!1.BB55 (CLASSIC)
DrWebLinux.BackDoor.Fgt.707
JiangminBackdoor.Linux.hhm
ZoneAlarmHEUR:Backdoor.Linux.Gafgyt.bl
Avast-MobileELF:Mirai-YN [Trj]
GDataLinux.Trojan.Gafgyt.B
TencentBackdoor.Linux.Gafgyt.df
SentinelOneDFI – Malicious ELF
AVGELF:Mirai-TX [Trj]

How to remove Linux/Gafgyt.AMV?

Linux/Gafgyt.AMV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment