Trojan

Trojan:Win32/Gozi!pz removal instruction

Malware Removal

The Trojan:Win32/Gozi!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gozi!pz virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Gozi!pz?


File Info:

name: AFAD418E5C52F37E17E6.mlw
path: /opt/CAPEv2/storage/binaries/1732228360938686998062247bf2494b2356b9008d18953ad4b6c3ba7d48829e
crc32: 4055282B
md5: afad418e5c52f37e17e67280019e5420
sha1: e5a7da525495dfd42e4fb41add2821066654a780
sha256: 1732228360938686998062247bf2494b2356b9008d18953ad4b6c3ba7d48829e
sha512: 3c19a0a88696a294207ee58b829b5c390c04aa25279c2d3f62df4183258253c3e86c7d7eec64e9dba589e16d86288d1720e1cf33398d51dafdfbabd9b6d544da
ssdeep: 12288:YhsRLPkCDt1EG2XVekhdeTKTfp3JxMcRCKfxgM:YhuLPkQ1bqAafxJxMcVx
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D0B42373B2D0C015C69D03B2EB9B7638BAF4C856E73846DFA7640D44847FB82E5949A3
sha3_384: 47b0a5ee9a6a575127a821d846736a30c0ff84eea2841f6e72587bf7c2cbd8784845a453abcbca7b3d307c47c83abae3
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2015-01-23 23:19:36

Version Info:

0: [No Data]

Trojan:Win32/Gozi!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.800032
FireEyeGeneric.mg.afad418e5c52f37e
SkyhighBehavesLike.Win32.Ransom.hc
McAfeeArtemis!AFAD418E5C52
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Redcap.75be3ac4
ArcabitTrojan.Razy.DC3520
BaiduWin32.Trojan.Kryptik.ii
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Virus.Ursnif-9769699-0
BitDefenderGen:Variant.Razy.800032
AvastWin32:Crypt-SWP [Trj]
SophosGeneric ML PUA (PUA)
DrWebTrojan.Siggen14.15918
EmsisoftGen:Variant.Razy.800032 (B)
IkarusTrojan-Spy.Agent
VaristW32/Agent.GUW.gen!Eldorado
AviraTR/Redcap.yigoa
MicrosoftTrojan:Win32/Gozi!pz
ViRobotTrojan.Win.Z.Razy.536576.HZ
GDataGen:Variant.Razy.800032
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R292416
Acronissuspicious
BitDefenderThetaAI:Packer.D2CED32A20
ALYacGen:Variant.Razy.800032
MAXmalware (ai score=86)
VBA32Trojan.Inject
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingTrojan.Generic@AI.95 (RDMK:J0FF3G/N37pGiRzcMrCFTw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.D179!tr
AVGWin32:Crypt-SWP [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Gozi!pz?

Trojan:Win32/Gozi!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment