Worm

Worm.GaoBot (file analysis)

Malware Removal

The Worm.GaoBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.GaoBot virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Worm.GaoBot?


File Info:

name: 2EAB89498E5BCED83297.mlw
path: /opt/CAPEv2/storage/binaries/c0a73fbe1ad9cde88c0c99325d2f8a988458012b08e148b88a5e53490ade67e8
crc32: 086733DD
md5: 2eab89498e5bced83297c309e4d4b722
sha1: a8752bc1a8e0eb45ba5c197df07e6d5cb6e18569
sha256: c0a73fbe1ad9cde88c0c99325d2f8a988458012b08e148b88a5e53490ade67e8
sha512: b2492c2da825f366f1e1c5447ef3f1ca501a6b22621c8ac158485195a0fad5e74d2c89ac5c66e89b4f27ab14558c898f3465b2d14f263a197d42c61e4e9db231
ssdeep: 768:wsN37vfSYrgRtnQz3Rqw+fxiIXd562ROy0tgpMtZq:wsN37nSxg+86BTPpgZq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2535D01D6098177F186A275064986725CB7B8B20F3871D3BBC6EFCD0EB96C9C1738A5
sha3_384: 6f9149ee38707dfae7506ecefc983f1f6fca902ba346c8f760dd4ca6af4f4b0bf5182dc140897c3d0836357d57a8e1a6
ep_bytes: 00000000000000000000000000000000
timestamp: 2106-02-07 06:28:15

Version Info:

0: [No Data]

Worm.GaoBot also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.261851
ClamAVWin.Worm.Mytob-203
FireEyeGeneric.mg.2eab89498e5bced8
McAfeeGenericRXAA-AA!2EAB89498E5B
CylanceUnsafe
VIPREGen:Variant.Fugrafa.261851
SangforTrojan.Win32.Save.a
Cybereasonmalicious.1a8e0e
CyrenW32/Ircbot.BCYP-6385
SymantecW32.Gaobot.gen!poly
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Fugrafa.261851
AvastWin32:HBPECrypt-A [Wrm]
TencentBackdoor.Win32.Ircbot.za
Ad-AwareGen:Variant.Fugrafa.261851
EmsisoftGen:Variant.Fugrafa.261851 (B)
TrendMicroTROJ_GEN.R03BC0OHE22
McAfee-GW-EditionBehavesLike.Win32.Generic.kz
Trapminemalicious.high.ml.score
SophosMal/Behav-004
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.4O6SLA
JiangminBackdoor/IRCBot.dvk
AviraTR/Downloader.Gen
ArcabitTrojan.Fugrafa.D3FEDB
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacGen:Variant.Fugrafa.261851
MAXmalware (ai score=80)
MalwarebytesWorm.GaoBot
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R03BC0OHE22
RisingTrojan.Generic@AI.98 (RDML:p+hT80IrSHneEXghga6Urg)
YandexTrojan.GenAsa!KfyPvSi9TRk
IkarusBackdoor.Win32.Agobot
MaxSecureVirus.Mabezat.Dam
FortinetW32/PossibleThreat
AVGWin32:HBPECrypt-A [Wrm]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.GaoBot?

Worm.GaoBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment