Trojan

Trojan:Win32/Gozi.RD!MTB (file analysis)

Malware Removal

The Trojan:Win32/Gozi.RD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi.RD!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Gozi.RD!MTB?


File Info:

name: F410A8450177FA00F302.mlw
path: /opt/CAPEv2/storage/binaries/a38876ebeddde9bcb8b2f6832d8bce68a5f5d1b6c436b3e67127115adf02ee90
crc32: 2946F7E6
md5: f410a8450177fa00f30265b831dbfacb
sha1: 5edbccd3c71140b54c23c6a7e1d948124748fa10
sha256: a38876ebeddde9bcb8b2f6832d8bce68a5f5d1b6c436b3e67127115adf02ee90
sha512: 7d6c1ac934278cd9eeb5d184dd23fd019207db3e54135d4c20f1aff1e8158251f63ff6436d73166df60f5764e9308f9b717d36fd5e4af53a0464518893f8f929
ssdeep: 6144:jClb7DSwhBEHzWpUfPNr+DRD5fWBuxBl11tbpuf:jClbrhB2zWSdWJZRxPPm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A544F1C1FAC942F1DEE7CAB0347AE919E7B1601C6424C952E7785F9AF52048C9BBD348
sha3_384: 641e02675d3b7a31acc8a88df202386ffe52277cc290cb1f4df9b3b1e74592aa9d3f933d2324cd82f6118c31666751b9
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2015-03-19 17:47:02

Version Info:

0: [No Data]

Trojan:Win32/Gozi.RD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ursnif.4!c
MicroWorld-eScanGen:Variant.Cerbu.198789
FireEyeGeneric.mg.f410a8450177fa00
SkyhighBehavesLike.Win32.Ransom.dc
McAfeeArtemis!F410A8450177
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Kryptik.iq
SymantecML.Attribute.HighConfidence
ElasticWindows.Generic.Threat
APEXMalicious
ClamAVWin.Packed.Razy-9797502-0
BitDefenderGen:Variant.Cerbu.198789
AvastWin32:WormX-gen [Wrm]
TACHYONTrojan/W32.Agent.262144.BDT
EmsisoftGen:Variant.Cerbu.198789 (B)
F-SecureTrojan.TR/AD.Tuscas.ooicb
DrWebTrojan.Inject1.53764
VIPREGen:Variant.Cerbu.198789
TrendMicroPE_URSNIF.E-O
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Ursnif.azk
GoogleDetected
AviraTR/AD.Tuscas.ooicb
VaristW32/S-ec931843!Eldorado
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Gozi.RD!MTB
ArcabitTrojan.Cerbu.D30885
GDataWin32.Trojan.PSE.122U285
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ursnif.R300845
BitDefenderThetaAI:FileInfector.1210116D11
ALYacGen:Variant.Cerbu.198789
MAXmalware (ai score=83)
VBA32SScope.Trojan.FakeAV.01681
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallPE_URSNIF.E-O
RisingTrojan.Generic@AI.100 (RDML:H3JsB9q0cs3hvjRcetOgRw)
YandexTrojan.GenAsa!RK3x+npEgzs
IkarusVirus.Win32.Ursnif
MaxSecureTrojan.Malware.74581998.susgen
FortinetW32/Agent.VHO!tr
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Gozi.RD!MTB?

Trojan:Win32/Gozi.RD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment