Trojan

Trojan.Linux.Gafgyt.5 (B) information

Malware Removal

The Trojan.Linux.Gafgyt.5 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Linux.Gafgyt.5 (B) virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine Trojan.Linux.Gafgyt.5 (B)?


File Info:

crc32: 13BC3716
md5: 56c71251ebd86c96b6a9c615424a6c8e
name: tmpo5g5204t
sha1: 17bbd0b109328e37c929d94613f1fecde0949ccf
sha256: 327f905463cbb4e5ef27c76498444dc2e75fa5660016d0e33354e2b459d6b254
sha512: e74db2d7c2198a6d15b9f21f08f4ece74ff09714a2b6ef679708b4002168f549c8f0ed2091f0ca9fd47beadfea6e749097d093bf985293408851e60f57880d39
ssdeep: 1536:S1duoZ+jYv50VGJtYYceZqncj5Wu1AHZUPb8UqSkGAeOmU+LEvpb0ramXZ:S1IoZ+jYWgJtXcLnEc1UPbJQGKm7LEvc
type: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, not stripped

Version Info:

0: [No Data]

Trojan.Linux.Gafgyt.5 (B) also known as:

MicroWorld-eScanGen:Variant.Trojan.Linux.Gafgyt.5
McAfeeLinux/HeliBot!56C71251EBD8
SangforMalware
ArcabitTrojan.Trojan.Linux.Gafgyt.5
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Linux/Gafgyt.ASH
TrendMicro-HouseCallBackdoor.Linux.BASHLITE.SMJC11
AvastELF:DDoS-Y [Trj]
ClamAVUnix.Trojan.Mirai-5607483-0
KasperskyHEUR:Backdoor.Linux.Gafgyt.bj
BitDefenderGen:Variant.Trojan.Linux.Gafgyt.5
NANO-AntivirusTrojan.Elf32.Gafgyt.hgvntv
RisingBackdoor.Gafgyt!8.56E (TFE:1D:WUIJ2BvJ1xJ)
Ad-AwareGen:Variant.Trojan.Linux.Gafgyt.5
EmsisoftGen:Variant.Trojan.Linux.Gafgyt.5 (B)
ComodoMalware@#z1vul8b77eqy
F-SecureMalware.LINUX/Gafgyt.osqme
DrWebLinux.BackDoor.Fgt.1427
ZillyaTrojan.Gafgyt.Linux.11578
TrendMicroBackdoor.Linux.BASHLITE.SMJC11
McAfee-GW-EditionLinux/HeliBot!56C71251EBD8
FortinetELF/Gafgyt.BJ!tr
FireEyeGen:Variant.Trojan.Linux.Gafgyt.5
SophosMal/Generic-S
IkarusTrojan.Linux.Gafgyt
CyrenELF/Trojan.PVSA-7
AviraLINUX/Gafgyt.osqme
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Linux.Gafgyt.bj
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AegisLabTrojan.Linux.Gafgyt.m!c
ZoneAlarmHEUR:Backdoor.Linux.Gafgyt.bj
Avast-MobileELF:DDoS-S [Trj]
CynetMalicious (score: 85)
AhnLab-V3Linux/Gafgyt.Gen44
ALYacGen:Variant.Trojan.Linux.Gafgyt.5
TencentLinux.Backdoor.Gafgyt.Sxop
SentinelOneDFI – Malicious ELF
GDataLinux.Trojan.Gafgyt.B
BitDefenderThetaGen:NN.Mirai.34106
AVGELF:DDoS-Y [Trj]
Qihoo-360Linux/Backdoor.745

How to remove Trojan.Linux.Gafgyt.5 (B)?

Trojan.Linux.Gafgyt.5 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment