Trojan

Trojan-Downloader.Win32.GoPIX (file analysis)

Malware Removal

The Trojan-Downloader.Win32.GoPIX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.GoPIX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan-Downloader.Win32.GoPIX?


File Info:

name: 7F40012AC961553A3B9B.mlw
path: /opt/CAPEv2/storage/binaries/64ecc4d34f45662b32387008b5d81b21bd995af399a6957ca2c1441756073307
crc32: 4A1142E9
md5: 7f40012ac961553a3b9b4f1c2e5611b1
sha1: b0b664f803797817ae0d2a18b1050ac43ebede4e
sha256: 64ecc4d34f45662b32387008b5d81b21bd995af399a6957ca2c1441756073307
sha512: df6f1ca6598e851526e1a22f3278bdc3a19a35b5fcd1cf35e2c1c93428e8a9eb71fce11384c012bda576e9b0d4d31b38bc76aaa5b3540951617ded337f78602b
ssdeep: 768:UxmFZA+CsE1nOE54ed7UFTDgWB2ZT0D3y1UpiUG1uTysx8FbgQDSSW2ap7PxWEr7:amFZk2E2YZT0Di1UE1upgbJqnxPxR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E43AF106760C827E9B34B7269B9677B8FF5D92254B48E4703002F4D7EA23C2AE1F761
sha3_384: 2de7c30130b857e5b3f8947f8c50cbd277b1093b6f776d4ce0ddcd882fcadfea1549c168c6d5c6bb86246dcacf548cb6
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:58:45

Version Info:

CompanyName: swellium
FileDescription: haxora
FileVersion: 4.10.0.5
LegalCopyright: (C) swellium
ProductName: voluntero
ProductVersion: 4.10.0.5
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.GoPIX also known as:

BkavW32.Common.AD852EE9
LionicTrojan.Win32.GoPIX.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70773410
ClamAVWin.Trojan.Jaik-9828282-0
FireEyeTrojan.GenericKD.70773410
SkyhighNSIS/Downloader.r
ALYacTrojan.GenericKD.70773410
Cylanceunsafe
K7AntiVirusTrojan ( 005ad2791 )
K7GWTrojan ( 005ad2791 )
SymantecTrojan Horse
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Downloader.Win32.GoPIX.gen
BitDefenderTrojan.GenericKD.70773410
AvastWin32:DangerousSig [Trj]
SophosMal/Generic-S
F-SecureTrojan.TR/Agent.aoxw
VIPRETrojan.GenericKD.70773410
TrendMicroTROJ_GEN.R002C0DF423
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.70773410 (B)
GDataTrojan.GenericKD.70773410
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Agent.aoxw
KingsoftWin32.Trojan-Downloader.GoPIX.gen
ArcabitTrojan.Generic.D437EAA2
ZoneAlarmHEUR:Trojan-Downloader.Win32.GoPIX.gen
MicrosoftTrojan:Win32/Rastreio.A!MTB
VaristW32/ABRisk.HISK-4062
AhnLab-V3Trojan/Win.Agent.C5435330
McAfeeArtemis!7F40012AC961
MAXmalware (ai score=89)
VBA32TrojanDownloader.GoPIX
MalwarebytesMalware.AI.1506826093
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DF423
AVGWin32:DangerousSig [Trj]
DeepInstinctMALICIOUS

How to remove Trojan-Downloader.Win32.GoPIX?

Trojan-Downloader.Win32.GoPIX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment