Trojan

Trojan.GofotIH.S16489613 information

Malware Removal

The Trojan.GofotIH.S16489613 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GofotIH.S16489613 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Writes to the spooler folder, potential vulnerability or printer driver install
  • Anomalous binary characteristics

How to determine Trojan.GofotIH.S16489613?


File Info:

name: F22EBEE63E181788A1BC.mlw
path: /opt/CAPEv2/storage/binaries/e6ecf5a65e3ca6c6764679d9f030cede7e73ba178b3b482eba2ee9d4ed67d5f5
crc32: F18FD3E2
md5: f22ebee63e181788a1bc15242374f3ef
sha1: a4fcf80d5cddd5f8f0bb7925b76b25406f4bf2ba
sha256: e6ecf5a65e3ca6c6764679d9f030cede7e73ba178b3b482eba2ee9d4ed67d5f5
sha512: dead7882652f4d60f3cc98d48bf9c791cda3784231fb52d133c57c3f1d6e4d7249a246860cd6d9fd978fc238117c756bec64331bb842784815a9e2a665149bff
ssdeep: 12288:kGzQYR4IeaAVB6ETW82Ku8UKfdndr6oSWcJTv8aGMoNUNaZrcJTv8aGMoNUNaZrY:k8lgaAVB6evW8UKlndrwDDDDDDDDDd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB56F850948E2C39CED37FB9785C42D3B3A16F988A3993EA58F785BA037EC1603D5911
sha3_384: 7eabe2432984bfd7294effc278db30b063c9206448020c6a45f53a18f42e7c6e2de5ad980a40c2c71a98ce012cad73b1
ep_bytes: 558bec83c4f0535657b8b4624500e83d
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Sunward Information Technology Co.Ltd
FileDescription: BarClientView.exe
FileVersion: 2010, 8, 6, 1
InternalName: BarClientView.exe
LegalCopyright: Sunward Information Technology Co.Ltd
OriginalFilename: BarClientView.exe
ProductName: BarClientView.exe
ProductVersion: 7, 1, 3, 0
Translation: 0x0804 0x03a8

Trojan.GofotIH.S16489613 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.31479
MicroWorld-eScanTrojan.GenericKD.47105118
FireEyeGeneric.mg.f22ebee63e181788
CAT-QuickHealTrojan.GofotIH.S16489613
McAfeeGenericR-HEL!F22EBEE63E18
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.13532
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.63e181
BitDefenderThetaAI:Packer.CB79629319
CyrenW32/Gofot.B.gen!Eldorado
ESET-NOD32a variant of Win32/Delf.OKR
APEXMalicious
ClamAVWin.Malware.Barys-6743002-0
KasperskyTrojan.Win32.Gofot.cnq
BitDefenderTrojan.GenericKD.47105118
NANO-AntivirusTrojan.Win32.Gofot.iccfvo
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b077b9
Ad-AwareTrojan.GenericKD.47105118
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.tz
EmsisoftTrojan.GenericKD.47105118 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47105118
JiangminTrojan/Cosmu.hji
AviraTR/Rogue.qpeipti
Antiy-AVLTrojan/Generic.ASMalwS.20FF76E
MicrosoftTrojan:Win32/Delf.OKR!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cosmu.R104888
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacTrojan.GenericKD.47105118
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.DLF
RisingTrojan.Clicker!1.64DF (CLASSIC)
YandexTrojan.Gofot!u9o6Pcsvswo
IkarusBackdoor.Win32.Hupigon
eGambitUnsafe.AI_Score_86%
FortinetW32/Delf.OKR!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.GofotIH.S16489613?

Trojan.GofotIH.S16489613 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment