Malware

Should I remove “Troj/Gozi-UC”?

Malware Removal

The Troj/Gozi-UC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Gozi-UC virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory

How to determine Troj/Gozi-UC?


File Info:

crc32: 21890329
md5: 8de47da0ad9fa2ef185710568d2ee9d8
name: 8DE47DA0AD9FA2EF185710568D2EE9D8.mlw
sha1: 6e7c86ad6eeee8df701df6cdefc8e5b536318875
sha256: 860d66118038d7f8b21b4f58d84d5e47fc7fc3a8e913e957699534601e68b714
sha512: 0f09340a0b1658b56f67956ea440a4ca17038a7157258b9cacce6ba37e2df1c429e7c97bd9777f9c76f5139cae1c57f7c145ddccd29b574f2a13b49bdd573740
ssdeep: 49152:AQU1aLhQhG5NUAgoOa8nBc0SmmdWwMLwktw4B8erqfn8+nFFQCxEsJwKQM:AfaNQh+NUABO/c0Y9AdBrqf8+gqJW
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Usual done Corporation. All rights reserved
InternalName: Didride Cutuse
FileVersion: 8.2.6.859
CompanyName: Usual done Corporation
ProductName: Usual donexae Rowfigure Temperatureblockxae
ProductVersion: 8.2.6.859
FileDescription: Usual done Rowfigure Temperatureblock
OriginalFilename: Thin.dll
Translation: 0x0409 0x04b0

Troj/Gozi-UC also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.13752
CAT-QuickHealTrojan.GenericPMF.S24367167
ALYacTrojan.GenericKDZ.79440
ZillyaTrojan.Kryptik.Win32.3593290
K7GWTrojan ( 00589b141 )
K7AntiVirusTrojan ( 00589b141 )
CyrenW32/Danabot.AP.gen!Eldorado
SymantecTrojan.Danabot
ESET-NOD32a variant of Win32/Kryptik.HNDR
AvastWin32:BotX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKDZ.79440
MicroWorld-eScanTrojan.GenericKDZ.79440
TencentMalware.Win32.Gencirc.10cf82f8
Ad-AwareTrojan.GenericKDZ.79440
SophosTroj/Gozi-UC
VIPRETrojan.Win32.Zbot.ata (v)
McAfee-GW-EditionGenericRXQN-TY!8DE47DA0AD9F
FireEyeTrojan.GenericKDZ.79440
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Agent.ktx
Antiy-AVLTrojan/Generic.ASMalwS.34C5A9B
MicrosoftTrojan:Win32/Danabot
GDataWin32.Trojan.PSE.QR0N15
AhnLab-V3Trojan/Win.Generic.C4744145
McAfeeGenericRXQN-TY!8DE47DA0AD9F
MAXmalware (ai score=83)
VBA32TrojanPSW.Panda
MalwarebytesSpyware.DanaBot
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.DA5E (CLASSIC)
IkarusTrojan-Banker.DanaBot
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.FMUS!tr
AVGWin32:BotX-gen [Trj]

How to remove Troj/Gozi-UC?

Troj/Gozi-UC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment