Trojan

Trojan:Win32/Gozi.GR!MTB removal guide

Malware Removal

The Trojan:Win32/Gozi.GR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi.GR!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Anomalous binary characteristics

How to determine Trojan:Win32/Gozi.GR!MTB?


File Info:

crc32: 940A2FDF
md5: bc57ff902ac558cb0c5d3ea64cd57b16
name: BC57FF902AC558CB0C5D3EA64CD57B16.mlw
sha1: fac8297c20c9ef3cd7b3e3e856dd4015902bdcbc
sha256: f9b2735ca40938ee87ed20a726504bf11204b1c8dcc69199dd2afa8cf8f504c6
sha512: 5c645d7b7f87c8f1ac55551b7bb7e021a157ab9bf6a18a2195a6d85a60f6489c398d572b8b0949eb12ac4c0d389799e2214a194f5e4533703d1fd91284806cd9
ssdeep: 24576:0hoiGIFOtJJ3hK/Qo+7LI7HnxVRS8fIiCDW:rJhZo8LI7HHRtnCDW
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009, Period There
InternalName: Touch.dll
FileVersion: 6.0.7.699
CompanyName: Period There
LegalTrademarks: Meeteach
ProductName: Meeteach
ProductVersion: 6.0.7.699
FileDescription: Meeteach
Translation: 0x0409 0x04b0

Trojan:Win32/Gozi.GR!MTB also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.36808362
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057ba061 )
K7AntiVirusTrojan ( 0057ba061 )
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HKPU
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
BitDefenderTrojan.GenericKD.36808362
MicroWorld-eScanTrojan.GenericKD.36808362
Ad-AwareTrojan.GenericKD.36808362
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.snnab@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36808362
EmsisoftTrojan.GenericKD.36808362 (B)
JiangminTrojan.Banker.Cridex.arj
AviraTR/AD.UrsnifDropper.lzrac
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Gozi.GR!MTB
ArcabitTrojan.Generic.D231A6AA
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan-Spy.Ursnif.VN76MW
McAfeeTrojan-FTSS!BC57FF902AC5
MAXmalware (ai score=88)
VBA32BScope.Trojan.Agent
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HKPU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Gozi.GR!MTB?

Trojan:Win32/Gozi.GR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment