Worm

Worm:Win32/Gaobot!pz removal tips

Malware Removal

The Worm:Win32/Gaobot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Gaobot!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Worm:Win32/Gaobot!pz?


File Info:

name: A9D395BB08630E7BBDBF.mlw
path: /opt/CAPEv2/storage/binaries/3787fe28e51ddf1eb988d4be6881b8ad04645d9fcf219880f03f5555668c044d
crc32: 6BBBD6AE
md5: a9d395bb08630e7bbdbfcdde3b341a48
sha1: d7de684b7724887e1eec4d283a820dc552892bf1
sha256: 3787fe28e51ddf1eb988d4be6881b8ad04645d9fcf219880f03f5555668c044d
sha512: e721f578161d947acc6182971c98a503b73884af84fa74bdac02a6ff1d0d14fed876ce6115d77da528f0e34a88e52420cc83814c65aa84ee6c36220d898b4ab1
ssdeep: 3072:mEp0ju3Sw3DhTkuWu3Sw3DhTkuWu3Sw3DhTkuwu3Sw3DhTkuWu3Sw3DhTkuWu3SW:m7IlpDlpDlp9lpDlpDlp9lpDlp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FC4491E1249E824C0F115B0C65A6D33543EDA69E728634367EFCAFB0BE1871466F89F
sha3_384: c280c8077957804f23b6e76f36fa42eee898039464989df4bfa4b0ba60deb68939981c3c9853b14c630d1039db3fc625
ep_bytes: e9550000005a565750515389d3e84801
timestamp: 2106-02-07 06:28:15

Version Info:

0: [No Data]

Worm:Win32/Gaobot!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.kYTK
tehtrisGeneric.Malware
ClamAVWin.Worm.Mytob-203
CAT-QuickHealWorm.Gaobot.Gen
SkyhighBehavesLike.Win32.Gaobot.ht
McAfeeGenericRXAA-AA!A9D395BB0863
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00553f0b1 )
BitDefenderGeneric.Malware.SI!dld!g.46B97B29
K7GWTrojan ( 00553f0b1 )
Cybereasonmalicious.b77248
Elasticmalicious (high confidence)
ESET-NOD32Win32/Mytob.QA
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.IRCBot.jt
AlibabaTrojan:Win32/Starter.ali1001008
NANO-AntivirusTrojan.Win32.Agobot.kanqgo
ViRobotWorm.Win32.Agobot.gen
MicroWorld-eScanGeneric.Malware.SI!dld!g.46B97B29
AvastWin32:HBPECrypt-A [Wrm]
RisingWorm.Mytob.hf (CLASSIC)
EmsisoftGeneric.Malware.SI!dld!g.46B97B29 (B)
F-SecureTrojan.TR/Downloader.Gen
DrWebWin32.HLLW.Agobot
ZillyaBackdoor.IRCBot.Win32.101936
TrendMicroMal_Bot
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a9d395bb08630e7b
SophosW32/Mytob-Fam
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/IRCBot.dvk
GoogleDetected
AviraTR/Downloader.Gen
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.Agobot.a
MicrosoftWorm:Win32/Gaobot!pz
XcitiumBackdoor.Win32.Agobot.hn0@1d9dgj
ArcabitGeneric.Malware.SI!dld!g.46B97B29
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
ZoneAlarmBackdoor.Win32.IRCBot.jt
GDataGeneric.Malware.SI!dld!g.46B97B29
VaristW32/Ircbot.BCYP-6385
AhnLab-V3Worm/Win32.IRCBot.R7768
Acronissuspicious
ALYacGeneric.Malware.SI!dld!g.46B97B29
VBA32Backdoor.IRCBot
Cylanceunsafe
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallMal_Bot
TencentBackdoor.Win32.Agobot.za
YandexTrojan.GenAsa!KfyPvSi9TRk
IkarusBackdoor.Win32.Agobot
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/AgoBot.fam!worm
BitDefenderThetaAI:Packer.6C81C1B01E
AVGWin32:HBPECrypt-A [Wrm]
PandaMalicious Packer
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Gaobot!pz?

Worm:Win32/Gaobot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment