Malware

What is “Linux/Gafgyt.AXI”?

Malware Removal

The Linux/Gafgyt.AXI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Linux/Gafgyt.AXI virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine Linux/Gafgyt.AXI?


File Info:

crc32: 3829B926
md5: e3ba6da588c338b775a2f30240adea50
name: tmpnml4z_rl
sha1: b6f4fda30404e97c13658e4fc102f3677435ae01
sha256: 38b1f5807377a9e0e25b795bac5fb16b072bea7a981a2f122d2df8aa1fe529dd
sha512: c79c8f0f26a748bb60599411b3a48642924f33a218054c94250ceaa9ce1d60c29d95414e3e492cf0a1aaed1dbf6a4138a2d16b3cc66a315abce498530d9e283e
ssdeep: 768:jSnGKgWNh6a79rd2Zm7blvjLPMG7r2aLMX1IJkD+NQkUNT33Ueyq:mnGKLhNBd2elvjJLMX1IJg+qyq
type: ELF 32-bit LSB executable, ARM, version 1, statically linked, stripped

Version Info:

0: [No Data]

Linux/Gafgyt.AXI also known as:

MicroWorld-eScanTrojan.GenericKDZ.66517
FireEyeTrojan.GenericKDZ.66517
ALYacTrojan.GenericKDZ.66517
SymantecTrojan.Gen.NPE
AvastELF:Svirtu-AA [Trj]
ClamAVUnix.Trojan.DarkNexus-7679166-0
GDataTrojan.GenericKDZ.66517
KasperskyHEUR:Backdoor.Linux.Mirai.b
BitDefenderTrojan.GenericKDZ.66517
Ad-AwareTrojan.GenericKDZ.66517
EmsisoftTrojan.GenericKDZ.66517 (B)
F-SecureMalware.LINUX/Gafgyt.sjvor
DrWebLinux.Mirai.2522
McAfee-GW-EditionGenericRXJS-UZ!E3BA6DA588C3
SophosMal/Generic-S
JiangminBackdoor.Linux.ehpm
AviraLINUX/Gafgyt.sjvor
MicrosoftTrojan:Script/Wacatac.C!ml
ArcabitTrojan.Generic.D103D5
ZoneAlarmHEUR:Backdoor.Linux.Mirai.b
Avast-MobileELF:Svirtu-AA [Trj]
CynetMalicious (score: 85)
McAfeeGenericRXJS-UZ!E3BA6DA588C3
MAXmalware (ai score=82)
ESET-NOD32a variant of Linux/Gafgyt.AXI
TencentBackdoor.Linux.Mirai.waw
IkarusTrojan.Linux.Mirai
FortinetELF/Mirai.A!tr
AVGELF:Svirtu-AA [Trj]

How to remove Linux/Gafgyt.AXI?

Linux/Gafgyt.AXI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment