Trojan

Trojan.Win32.Gobot.blu removal instruction

Malware Removal

The Trojan.Win32.Gobot.blu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Gobot.blu virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Gobot.blu?


File Info:

name: C5C3A000509C99AE6635.mlw
path: /opt/CAPEv2/storage/binaries/7681e432242ab14c3ef759c2847ad933db53af3531ce0d33c1cba9e048b84f44
crc32: 31EB245C
md5: c5c3a000509c99ae6635a83b25b797e4
sha1: c007ce53b929498a42cbf5673983a803ded7d37d
sha256: 7681e432242ab14c3ef759c2847ad933db53af3531ce0d33c1cba9e048b84f44
sha512: 82d5db69368248cbbdab811c8c2faf919be14f19cce79c8cb674c80b3e0abca2c7ccbd7c4dbabc5e6c8d8269261d1a990e6af0d4a6476de360c03bb270b755c5
ssdeep: 98304:0GaF7i77iWKooxpNz0u4RUIYIrMsObAyujJrljtjwfFV6Ijs:sVi3iWKooxpNz0u4RUIYIrMsObAyu1lB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BF51203A5A5F0E0E706B0F184BB6B7681F3A04A72121A979797EC795C211B0B17B77E
sha3_384: 9faf9dcc8b3229d691bb5483d11e37b2cf46f43f18c9d3d6372135b268495bf696b10b6fc7265aafbf71709deeba96df
ep_bytes: 558bec6aff68605e46006870dc430064
timestamp: 2014-11-18 02:20:15

Version Info:

Comments: 桌面工具程序
CompanyName: 话语科技
FileDescription: 即时天气安装包程序
FileVersion: 1, 0, 0, 8
InternalName: InStaller
LegalCopyright: 话语科技版权所有 (C) 2014
LegalTrademarks:
OriginalFilename: InStaller.EXE
PrivateBuild:
ProductName: 即时天气
ProductVersion: 1, 0, 0, 8
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.Win32.Gobot.blu also known as:

LionicTrojan.Win32.Gobot.mqkp
Elasticmalicious (high confidence)
FireEyeGeneric.mg.c5c3a000509c99ae
CAT-QuickHealDownloader.Agent.22444
McAfeePUP-FRD
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 005292311 )
AlibabaMalware:Win32/km_24f52.None
K7GWRiskware ( 005292311 )
CrowdStrikewin/malicious_confidence_60% (W)
VirITTrojan.Win32.DownLoader12.BJPP
CyrenW32/ABRisk.LYZE-8001
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kuping.J potentially unwanted
APEXMalicious
ClamAVWin.Malware.Gobot-6988244-0
KasperskyTrojan.Win32.Gobot.blu
TencentMalware.Win32.Gencirc.13ed2b37
F-SecureHeuristic.HEUR/AGEN.1340055
DrWebTrojan.DownLoader17.43266
TrendMicroTROJ_GEN.R011C0PHP23
McAfee-GW-EditionPUP-FRD
Trapminesuspicious.low.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Gobot.ae
GoogleDetected
AviraHEUR/AGEN.1340055
XcitiumApplication.Win32.Kuping.B@6y68qo
MicrosoftPUA:Win32/Kuping
ZoneAlarmTrojan.Win32.Gobot.blu
GDataWin32.Adware.Kuping.B
CynetMalicious (score: 99)
VBA32Trojan.Gobot
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R011C0PHP23
RisingTrojan.Gobot!8.100 (TFE:5:HcdS1YRmPzD)
YandexRiskware.Agent!HkTZJuHxZ9g
IkarusTrojan.Win32.Gobot
FortinetRiskware/Kuping
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Gobot.blu?

Trojan.Win32.Gobot.blu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment