Trojan

Trojan.Win32.Gorgon.eyy removal guide

Malware Removal

The Trojan.Win32.Gorgon.eyy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Gorgon.eyy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
cyber-access.co.uk

How to determine Trojan.Win32.Gorgon.eyy?


File Info:

crc32: E97C938F
md5: 7130005b00126ba5ba6544afc487c951
name: 7130005B00126BA5BA6544AFC487C951.mlw
sha1: 9365a6e8194c6082cf4048c1ce0b6214e4addb75
sha256: fd65011c3a788492890b0c9e1da2c96de6e5e2213f6db7153b7a6e6e127d795d
sha512: d6d2c57485a3edb3542d00a8dfbf7ff49d2a9482672b5122dfaa91ee0675fac5273edba8366eaff6ee37ccfe5dcfc67c807c82590517e5cd2fcb3e9efbdc54a8
ssdeep: 3072:5Mv2i4N0m++4TNw8N5//nKbOZJRcVJCQ4Sz3wWJVy7CI8wIT:5Mv2i82rN5/SCfSDDwwVyWsU
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Gorgon.eyy also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35736116
FireEyeGeneric.mg.7130005b00126ba5
CAT-QuickHealTrojan.Gorgon
Qihoo-360Win32/Trojan.88c
McAfeeGenericRXAA-AA!7130005B0012
CylanceUnsafe
AegisLabTrojan.Win32.Gorgon.4!c
SangforMalware
K7AntiVirusTrojan ( 00574bdd1 )
BitDefenderTrojan.GenericKD.35736116
K7GWTrojan ( 00574bdd1 )
Cybereasonmalicious.8194c6
BitDefenderThetaGen:NN.ZexaF.34700.huZ@aGfl!goi
CyrenW32/Kryptik.CRS2.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HIGU
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Razy-9810657-0
KasperskyTrojan.Win32.Gorgon.eyy
AlibabaTrojan:Win32/Gorgon.eee84e12
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Agent.121856.SK
RisingMalware.Undefined!8.C (TFE:2:5GWEcV7ODrC)
Ad-AwareTrojan.GenericKD.35736116
SophosMal/Generic-S
ComodoMalware@#2xwjhlrybo947
F-SecureTrojan.TR/AD.LokiBot.jkrhk
DrWebBackDoor.SpyBotNET.25
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
EmsisoftTrojan.GenericKD.35736116 (B)
IkarusTrojan.MSIL.Agent
JiangminTrojan.PSW.MSIL.bbdb
AviraTR/AD.LokiBot.jkrhk
MAXmalware (ai score=100)
KingsoftWin32.Troj.Gorgon.e.(kcloud)
MicrosoftTrojan:Win32/FormBook.FE!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2214A34
AhnLab-V3Malware/Win32.RL_Generic.R358598
ZoneAlarmTrojan.Win32.Gorgon.eyy
GDataTrojan.GenericKD.35736116
CynetMalicious (score: 100)
VBA32BScope.Trojan.Winlock
ALYacTrojan.GenericKD.35736116
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R067C0DLK20
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_91%
FortinetMalicious_Behavior.SB
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Gorgon.eyy?

Trojan.Win32.Gorgon.eyy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment