Trojan

Trojan:Win32/Gozi.RH!MTB removal guide

Malware Removal

The Trojan:Win32/Gozi.RH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi.RH!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Gozi.RH!MTB?


File Info:

name: 2689BCE4B0F4F1D104A3.mlw
path: /opt/CAPEv2/storage/binaries/37e3137a3554f9cec4df8eddc84f0018d965eac6ce51a993b20facbee95dd280
crc32: 47812962
md5: 2689bce4b0f4f1d104a384dd7e3e89cd
sha1: 80b9a3c394b0a1229e3e42b960db9dd87d290497
sha256: 37e3137a3554f9cec4df8eddc84f0018d965eac6ce51a993b20facbee95dd280
sha512: 0c4ede2b5ebdfda392d15c36442d2a8e04cd763419488f9f726db0f4e2d9ed13acb65acecadc3500c48367557c2ea4c469f2b1cb04a66479b0d72576a3d2a9ba
ssdeep: 6144:iTZBx+7jsPTl/N80J849j3si2Hw2Kfl0OA5P1rh/YwOnhu58jT7FWQ+ICBFQ5jyy:IZP+7jsZS0r59Qw3RxjkeP
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T16CB46CA8374075BAC392517A748F0F0F727944DC648CCA98F968C8DA23AD94B5637F78
sha3_384: 1804b82bf075d91294d3e4195622289b2c0cf7a477343bf202b5bab7f6d1a867f377871258acdafbf45bbf14931c5a0d
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2022-09-20 09:52:40

Version Info:

0: [No Data]

Trojan:Win32/Gozi.RH!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gozi.10!c
Elasticmalicious (high confidence)
DrWebTrojan.Gozi.889
MicroWorld-eScanGen:Variant.Doina.43693
ClamAVWin.Malware.Icedid-9970557-0
FireEyeGeneric.mg.2689bce4b0f4f1d1
SkyhighBehavesLike.Win32.Infected.hm
McAfeeGenericRXAA-AA!2689BCE4B0F4
Cylanceunsafe
VIPREGen:Variant.Doina.43693
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005987b61 )
AlibabaTrojan:Win32/Kryptik.df6e9764
K7GWTrojan ( 005987b61 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Doina.DAAAD
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQWG
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Banker.Win32.Qbot.gen
BitDefenderGen:Variant.Doina.43693
AvastWin32:BotX-gen [Trj]
TencentMalware.Win32.Gencirc.13fed427
EmsisoftGen:Variant.Doina.43693 (B)
F-SecureHeuristic.HEUR/AGEN.1300400
ZillyaTrojan.Kryptik.Win32.4503861
TrendMicroTrojanSpy.Win32.URSNIF.YXEAZZ
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GoogleDetected
AviraHEUR/AGEN.1300400
KingsoftWin32.Troj.Banker.a
MicrosoftTrojan:Win32/Gozi.RH!MTB
ZoneAlarmUDS:Trojan-Banker.Win32.Qbot.gen
GDataGen:Variant.Doina.43693
VaristW32/Ursnif.EK.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R521858
ALYacGen:Variant.Doina.43693
MAXmalware (ai score=100)
VBA32TrojanBanker.Gozi
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.YXEAZZ
RisingTrojan.Gozi!8.E3A4 (TFE:5:gq90Tznmq1E)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.188245814.susgen
FortinetW32/Kryptik.HQWG!tr
AVGWin32:BotX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Gozi.RH!MTB?

Trojan:Win32/Gozi.RH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment