Trojan

Trojan.Win32.Gofot.vho removal guide

Malware Removal

The Trojan.Win32.Gofot.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Gofot.vho virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Gofot.vho?


File Info:

crc32: DE7D5D44
md5: 4f4605993ac067844987b6aaf0078bcb
name: 4F4605993AC067844987B6AAF0078BCB.mlw
sha1: f07a6a48b41c75f80b36aa68ebb49ec5b71cdb91
sha256: c52696a0e3831f2632250f4b57c9d4316689cbe29ee6058dfd57007ea1069804
sha512: 0b73b222740aacaa1a8aa74061fccae4ed5f80a98baedd3724f447588b47eb3c46fe3ff96d483b38cc0465688526658d839878e240e437cb080a1af7c9c4719c
ssdeep: 6144:eyJHQdBQp/bnGgiO5ngpLR7q0m1oyFwYrkn9OZaFo7:egHQdBq/bnGgxkR7tWoDYwyOo7
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
ProductVersion: 2.1.0.7
ProductName: x8f85x52a9x68c0x6d4bx6a21x5757
FileVersion: 2.1.0.7
FileDescription: x5e94x7528x7a0bx5e8fx6269x5c55x6a21x5757
Translation: 0x0804 0x04b0

Trojan.Win32.Gofot.vho also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.57326
ClamAVWin.Malware.Zusy-9645327-0
CAT-QuickHealTrojan.GofotPMF.S16126772
McAfeeGenericRXLF-QQ!4F4605993AC0
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1345344
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00564a041 )
K7AntiVirusTrojan ( 00564a041 )
CyrenW32/S-4eb9485d!Eldorado
ESET-NOD32a variant of Win32/Agent.ACCK
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Gofot.vho
BitDefenderGen:Variant.Zusy.306697
NANO-AntivirusTrojan.Win32.Gofot.hnakne
MicroWorld-eScanGen:Variant.Zusy.306697
TencentMalware.Win32.Gencirc.10cdfebf
VIPRETrojan.Win32.Generic!BT
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gofot.asx
AviraHEUR/AGEN.1138398
Antiy-AVLTrojan/Generic.ASMalwS.3092845
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/CryptInject.SBR!MSR
GDataGen:Variant.Zusy.306697
TACHYONTrojan/W32.Gofot.280614
AhnLab-V3Trojan/Win32.Agent.R341889
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=81)
MalwarebytesGeneric.Trojan.Injector.DDS
PandaTrj/Genetic.gen
RisingAdware.AdPop!1.BEEF (CLASSIC)
YandexTrojan.Agent!LPdvoBAu/YM
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.102608371.susgen
FortinetW32/Agent.ACCK!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan.Win32.Gofot.vho?

Trojan.Win32.Gofot.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment