Trojan

Trojan:Win32/Gozi.GP!MTB (file analysis)

Malware Removal

The Trojan:Win32/Gozi.GP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi.GP!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Gozi.GP!MTB?


File Info:

crc32: 08DAE3F1
md5: a65d542d8de92c2382a2b5b2e718a6a3
name: A65D542D8DE92C2382A2B5B2E718A6A3.mlw
sha1: c1855439825ba604e9ce431a7bc63863ad71a4e7
sha256: 532bc80351a659699d32d8f10760dca714cb395997cf0667e9631983d1b3a773
sha512: 9404fbb79d7423fc5cda56ff9c22d4c48c6d1bf686c82dc1cc531e5a8ced31ea13e1062808df6c045ea0f44318d819861a5caf7b85dcdc54a79a2bffc7fada47
ssdeep: 24576:HQfpzjXPgfe8CJV4X+IBIJ3cazaLwj1mCG9CpNiLi:IFDgaJV4OaIRj150CpNiLi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Gozi.GP!MTB also known as:

DrWebTrojan.Gozi.803
ClamAVWin.Trojan.Johnnie-9854285-0
ALYacGen:Variant.Zusy.378666
CylanceUnsafe
ZillyaTrojan.Ursnif.Win32.12080
SangforTrojan.Win32.Gozi.GP
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Ursnif.d4c63167
K7GWSpyware ( 005690661 )
K7AntiVirusSpyware ( 005690661 )
CyrenW32/Ursnif.DQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Ursnif.CG
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.378666
NANO-AntivirusTrojan.Win32.Gozi.iumage
MicroWorld-eScanGen:Variant.Zusy.378666
Ad-AwareGen:Variant.Zusy.378666
ComodoTrojWare.Win32.Agent.faiqo@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FTSS!A65D542D8DE9
FireEyeGen:Variant.Zusy.378666
EmsisoftTrojan-Spy.Ursnif (A)
JiangminTrojan.Agent.dgmy
AviraTR/Spy.Ursnif.ozghq
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Gozi.GP!MTB
ArcabitTrojan.Zusy.D5C72A
GDataGen:Variant.Zusy.378666
AhnLab-V3Trojan/Win.Agent.C4435087
McAfeeTrojan-FTSS!A65D542D8DE9
MAXmalware (ai score=85)
VBA32Trojan.Agent
MalwarebytesTrojan.Ursnif
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDR21
RisingSpyware.Ursnif!1.D578 (CLOUD)
YandexTrojanSpy.Ursnif!vDsZBfk4zy4
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.HKPU!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Trojan:Win32/Gozi.GP!MTB?

Trojan:Win32/Gozi.GP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment