Trojan

Trojan.Rasftuby.Gen.10 removal tips

Malware Removal

The Trojan.Rasftuby.Gen.10 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Rasftuby.Gen.10 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • A possible cryptomining command was executed
  • A cryptomining command containing a stratum protocol address was executed

Related domains:

xmr.pool.minergate.com

How to determine Trojan.Rasftuby.Gen.10?


File Info:

crc32: B6D4348A
md5: 0da20df5f8af1c44e234620e9fb54e0f
name: pubgergpj.exe
sha1: eef2b5a6418f58919adf719acdfe6696c098f97a
sha256: c9689469e63157d448c65b5a8f5a6f0f5e242c438cf15d31c602e07acd1a90b8
sha512: f1804ab83d7bbd9902a91c2355326f8196c7b3fc23c2edb5553b64fa8ef5fa76997240eb33597ba3f13274b73ed2edcfb1f0e177d1c856ecea328d3827b4b844
ssdeep: 49152:nJ3j2jQs63gw/VwPVQEaGGXvgOwF1wXw26i5NLbXqBG2:J3j2jEQw/8eXI71sw2F734
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Rasftuby.Gen.10 also known as:

MicroWorld-eScanTrojan.Rasftuby.Gen.10
Qihoo-360Win32/Trojan.a50
McAfeeArtemis!0DA20DF5F8AF
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Rasftuby.Gen.10
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5f8af1
SymantecTrojan.Gen.MBT
APEXMalicious
GDataTrojan.Rasftuby.Gen.10
KasperskyTrojan.Win32.Miner.tngi
NANO-AntivirusTrojan.Win32.Miner.eycjbu
TencentWin32.Trojan.Miner.Iso
Endgamemalicious (high confidence)
EmsisoftTrojan.Rasftuby.Gen.10 (B)
ComodoMalware@#10ummnf7ieusb
DrWebTrojan.MulDrop7.63478
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0da20df5f8af1c44
SophosMal/Generic-S
IkarusTrojan.BAT.CoinMiner
AviraTR/CoinMiner.vgfvi
MAXmalware (ai score=83)
ArcabitTrojan.Rasftuby.Gen.10
ZoneAlarmTrojan.Win32.Miner.tngi
MicrosoftTrojan:Win32/Skeeyah.A!rfn
Acronissuspicious
PandaTrj/CI.A
ESET-NOD32BAT/CoinMiner.ACG
FortinetBAT/CoinMiner.ACG!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan.Rasftuby.Gen.10?

Trojan.Rasftuby.Gen.10 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment