Malware

Win32.Gosys.A (file analysis)

Malware Removal

The Win32.Gosys.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Gosys.A virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32.Gosys.A?


File Info:

crc32: 9C3B0048
md5: 18f444cd79350ad60ca0aff8b866bc1d
name: V5_managerAdmin.exe
sha1: 6a6d843618ec023b4671c19d620ce4b58f1e9e83
sha256: 47bc4c0694ca8956d165f08099eec9791e41845da3d1a93ef169b5dddacac5c1
sha512: 25b60866bed3cdc421217b693e851443ba68cbc93e4537877b0b6e7ede22ef4c970d7c19fd2b062c7a16820a15f91642872cb82ed58eaf9bd50319661b11fbe9
ssdeep: 24576:U5xolYQY6gHEq86ClFzYndeGz9Vw0H9Gt3rKzVP7iCJa2lzrhggmWWaFhqMfzCUS:3YZHIXYlP2KDdwT3pyxTtzVKHB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Win
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: Win.exe

Win32.Gosys.A also known as:

BkavW32.VB.Swisyn.PE
MicroWorld-eScanWin32.Gosys.A
FireEyeGeneric.mg.18f444cd79350ad6
CAT-QuickHealTrojan.Swisyne.A3
McAfeeW32/Swisyn.ag
CylanceUnsafe
VIPRETrojan-PWS.Win32.VB.cu (v)
SangforMalware
K7AntiVirusTrojan ( 0040f0591 )
BitDefenderWin32.Gosys.A
K7GWTrojan ( 0040f0591 )
Cybereasonmalicious.d79350
TrendMicroPE_MOFKSYS.A
BaiduWin32.Trojan.VB.at
CyrenW32/VB.AD.gen!Eldorado
SymantecW32.Gosys
TotalDefenseWin32/VB.BOP
APEXMalicious
AvastWin32:Sality
ClamAVWin.Virus.Sality:1-6335700-1
GDataWin32.Gosys.A
KasperskyTrojan.Win32.Swisyn.bner
AlibabaTrojanPSW:Win32/Swisyn.3194b0a1
NANO-AntivirusTrojan.Win32.Swisyn.efyboj
TencentTrojan.Win32.Swisyn.f
Ad-AwareWin32.Gosys.A
SophosTroj/VB-JVT
ComodoTrojWare.Win32.VB.OSKB@4pc2ok
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.Siggen6.54687
ZillyaTrojan.Swisyn.Win32.32298
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Swisyn.vh
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Swisyn!O
EmsisoftWin32.Gosys.A (B)
IkarusTrojan-Spy.MSIL.Omaneat
F-ProtW32/VB.AD.gen!Eldorado
JiangminTrojan/Swisyn.rmj
MaxSecureTrojan.Swisyn.BNER
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Swisyn.bner
Endgamemalicious (high confidence)
ArcabitWin32.Gosys.A
ZoneAlarmTrojan.Win32.Swisyn.bner
MicrosoftPWS:Win32/VB.CU
AhnLab-V3Trojan/Win32.Swisyn.R1452
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34106.Io3@a4DcVwni
ALYacWin32.Gosys.A
VBA32MAS.Trojan.VB.01049
MalwarebytesTrojan.VBCrypt
PandaGeneric Malware
ZonerTrojan.Win32.47063
ESET-NOD32Win32/VB.OSK
TrendMicro-HouseCallPE_MOFKSYS.A
RisingTrojan.QOT!1.6519 (CLOUD)
YandexTrojan.VBGent.Gen.471
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Swisyn.BNER!tr
WebrootW32.Trojan.Gen
AVGWin32:Sality
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Virus.VBViking.N

How to remove Win32.Gosys.A?

Win32.Gosys.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment