Trojan

Trojan-Banker.Win32.Gozi.ws removal tips

Malware Removal

The Trojan-Banker.Win32.Gozi.ws is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Gozi.ws virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Trojan-Banker.Win32.Gozi.ws?


File Info:

crc32: 20ECE8B6
md5: 67f91f2830694dbc91600c935dc9d467
name: 67F91F2830694DBC91600C935DC9D467.mlw
sha1: 9097977b31054574053c3876589394a5cf17d3fd
sha256: d035dc004bad85de3835fbc2ddba770a647f682965bb5378edb3b65410e93e09
sha512: a71bc61dede0ca4c259b9aeecc647b0f861cd7cff8287fabfff12aaba103ffb5c7d758d19bb82a4ba34a3b2443dbb43598828d3bf8c4074b0efc7837fd13e56e
ssdeep: 24576:MptUIbWTbnKFdqJRJHvQ0pzkklFMCUWjZrn+gh9N9+I9:MHUIEbnKFdqJXVyAZaW39
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 6, 2, 4067, 1795
CompanyName: CropBring Pa
LegalTrademarks: Paper Figure
ProductName: Paper Figure
ProductVersion: 6, 2, 4067, 1795
FileDescription: Paper Figure
OriginalFilename: Paper Figure.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Gozi.ws also known as:

K7AntiVirusTrojan ( 00531b351 )
LionicTrojan.Win32.Generic.m9uu
DrWebTrojan.Siggen7.49533
CynetMalicious (score: 100)
ALYacSpyware.Ursnif
CylanceUnsafe
ZillyaTrojan.Gozi.Win32.255
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanBanker:Win32/Ursnif.a1010055
K7GWTrojan ( 00531b351 )
Cybereasonmalicious.830694
ESET-NOD32a variant of Win32/Kryptik.GGVS
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.Gozi.ws
BitDefenderGen:Heur.Mint.Zard.53
NANO-AntivirusTrojan.Win32.Gozi.fcjagj
MicroWorld-eScanGen:Heur.Mint.Zard.53
TencentWin32.Trojan-banker.Gozi.Wsar
Ad-AwareGen:Heur.Mint.Zard.53
ComodoMalware@#1m81eedn2ki2b
BitDefenderThetaGen:NN.ZexaF.34294.ur0@aqCfzDhi
VIPRETrojan.Win32.Zbot.ata (v)
TrendMicroTrojanSpy.Win32.URSNIF.SMKA0.hp
FireEyeGeneric.mg.67f91f2830694dbc
EmsisoftGen:Heur.Mint.Zard.53 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Gozi.ea
WebrootW32.Trojan.Emotet
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.26234F2
MicrosoftTrojan:Win32/Ursnif.A!MTB
GDataGen:Heur.Mint.Zard.53
AhnLab-V3Trojan/Win32.Injector.C2524701
McAfeeUrsnif-FPVB!67F91F283069
VBA32TrojanBanker.Gozi
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMKA0.hp
RisingTrojan.Generic@ML.97 (RDML:e+EkDmf/jm/bT1FlbN/r/g)
YandexTrojan.PWS.Gozi!k3S1nh4SqRY
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Gozi.AXN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.Gozi.ws?

Trojan-Banker.Win32.Gozi.ws removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment