Trojan

About “Trojan:Win32/Gozi.RF!MTB” infection

Malware Removal

The Trojan:Win32/Gozi.RF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi.RF!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Gozi.RF!MTB?


File Info:

name: CE948AF6317B42178ACD.mlw
path: /opt/CAPEv2/storage/binaries/510facc1d5c4b2bdab1560c69d14036e0a5d8fee43a9ee7459e86e95e76ce6df
crc32: F5B633B0
md5: ce948af6317b42178acdf16190a6502a
sha1: 63e8daef592e5ebc5c91cd3d4488f4aba0dad24d
sha256: 510facc1d5c4b2bdab1560c69d14036e0a5d8fee43a9ee7459e86e95e76ce6df
sha512: 1996a2034650d8cd41921c5270802d0b24a2b0b8848b11d46556fde712c20ccb86ce7f9b255486671d3f83818a1c28321486f127d0b18972654ecbb106b9cf33
ssdeep: 98304:CStvimZ61EpbhNQ3obcEffDvnh88mNuHMiABZlZlpGiuKvBGMQ9jft:CStZO+bjQs7nhVPPiXHGbkAhlt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19956127352970149EAE9CC3A86377DF475F6133646439C78ADE6ECC529328E6E123883
sha3_384: 2084dc7442e61318059e0321374e646211d717ed319b42bed5a60d0c398dbd63af73fcce4a959d54a1ce31aab5f66e67
ep_bytes: 558bec83ec0c837d08017508a14c0d44
timestamp: 2013-04-01 05:16:40

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Trojan:Win32/Gozi.RF!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.ce948af6317b4217
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXCQ-PF!CE948AF6317B
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.Ransom.Cerber.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a7b881 )
K7GWTrojan ( 005a7b881 )
Cybereasonmalicious.f592e5
BitDefenderThetaGen:NN.ZexaF.36738.@Z1@aOeVUGoc
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AXVE
APEXMalicious
ClamAVWin.Packed.Cafiko-10001442-0
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.ShipUp.bqpsur
AvastWin32:Agent-ARAC [Trj]
TencentTrojan.Win32.Shipup.xb
EmsisoftTrojan.Ransom.Cerber.1 (B)
F-SecureTrojan.TR/Crypt.Agent.ypdkd
BaiduWin32.Trojan.Agent.eq
ZillyaTrojan.Kryptik.Win32.4326945
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
GDataTrojan.Ransom.Cerber.1
GoogleDetected
AviraTR/Crypt.Agent.ypdkd
VaristW32/Gepys.BG.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
MicrosoftTrojan:Win32/Gozi.RF!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R605164
Acronissuspicious
ALYacTrojan.Ransom.Cerber.1
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.ShipUp.bqa
FortinetW32/Agent.534A!tr
AVGWin32:Agent-ARAC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Gozi.RF!MTB?

Trojan:Win32/Gozi.RF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment