Trojan

Trojan:Win32/Gozi.ARJ!MTB removal

Malware Removal

The Trojan:Win32/Gozi.ARJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi.ARJ!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Gozi.ARJ!MTB?


File Info:

crc32: 8CB3A8A1
md5: 61c5b521ec479f3a56b2e0ae17dc7dae
name: 3dtap.exe
sha1: f6b5364aee4f00d65ae85de28b6ed43e5acba394
sha256: 89b0d560210534b575e35145143d13049cd70e02ed5a1bfbae9b251b52c9034f
sha512: 8b7d70338b63280e89af326ef580ddd2095457f57ac2c1a630fe737bd2db659ec727cde7499aa20d3001071b4e118a9fd830469223d0253c86443689dd786422
ssdeep: 6144:HRUKClejH/OpOR9UgnrJUuCy6vPBwzqkVzdZ19zNVgmpUt:HCp0jH/Op7RZzBwVt19zNa4Ut
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2012 Oleg N. Scherbakov
InternalName: 7ZSfxMod
FileVersion: 1.6.0.2712
CompanyName: Oleg N. Scherbakov
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
FileDescription: 7z Setup SFX (x86)
OriginalFilename: 7ZSfxMod_x86.exe
Translation: 0x0000 0x04b0

Trojan:Win32/Gozi.ARJ!MTB also known as:

BkavW32.DownloadExtatsF.Trojan
MicroWorld-eScanDropped:Trojan.GenericKDZ.67418
FireEyeDropped:Trojan.GenericKDZ.67418
CAT-QuickHealTrojan.Multi
McAfeeArtemis!61C5B521EC47
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005676e91 )
BitDefenderDropped:Trojan.GenericKDZ.67418
K7GWTrojan ( 005676e91 )
CrowdStrikewin/malicious_confidence_80% (W)
TrendMicroTROJ_GEN.R002C0DEQ20
BitDefenderThetaGen:NN.ZexaF.34122.ryW@au!HyxjG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HDPQ
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
GDataDropped:Trojan.GenericKDZ.67418
KasperskyTrojan.Win32.Agent.xadvet
AlibabaTrojan:Win32/Kryptik.9ad80881
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Agent.Wopx
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.picnv
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
EmsisoftDropped:Trojan.GenericKDZ.67418 (B)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.uvenm
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Gozi
MicrosoftTrojan:Win32/Gozi.ARJ!MTB
ArcabitTrojan.Generic.D1075A
AhnLab-V3Dropper/Win32.Agent.C4109666
ZoneAlarmTrojan.Win32.Agent.xadvet
VBA32BScope.Trojan.Download
ALYacDropped:Trojan.GenericKDZ.67418
Ad-AwareDropped:Trojan.GenericKDZ.67418
MalwarebytesTrojan.Dropper.SFX
TrendMicro-HouseCallTROJ_GEN.R002C0DEQ20
RisingTrojan.Kryptik!1.C698 (CLASSIC)
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HPDO!tr
WebrootW32.Trojan.Gen
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.aee4f0
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.aaf

How to remove Trojan:Win32/Gozi.ARJ!MTB?

Trojan:Win32/Gozi.ARJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment