Trojan

Trojan.Win32.Gasti.tm removal guide

Malware Removal

The Trojan.Win32.Gasti.tm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Gasti.tm virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for fileless persistence
  • A script or command line contains a long continuous string indicative of obfuscation
  • Harvests cookies for information gathering
  • Created a service that was not started
  • Attempts to execute suspicious powershell command arguments

How to determine Trojan.Win32.Gasti.tm?


File Info:

name: 61EFF768A47E729FE2AB.mlw
path: /opt/CAPEv2/storage/binaries/e00ad6f41bbd33b1d3c9940a942822c8b4d418bf771082d9bb8ce21fc4ccff62
crc32: 848EDDAC
md5: 61eff768a47e729fe2abda3585585fe4
sha1: f25674ff6509dcb8a621639d8a4c7eda4488a315
sha256: e00ad6f41bbd33b1d3c9940a942822c8b4d418bf771082d9bb8ce21fc4ccff62
sha512: d874bbeb5bcdfe13e34f18ff230aade1e80f1dc7f3e7d1fd44f4bb254d1ff49ac512880342cefe9356c80989fa051357c4af5d56ac5152db692edcd5e4f90e15
ssdeep: 98304:ozBSKSOPOBfKVmxqclpqrzBBuVW709lJbssy3soT8LHEYlfU+CYO2xqu5u5K1Y38:obSOd8x1KrSQ70gFgLkYG+CYO2xqu5un
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T15E16014573E908E4F5F76A3489764616EA737C415B38C69F13A0826E2F73AD09C39B23
sha3_384: 2aa333a687c4188c6ce2263b67cb6ae38d555b510615d5957e1c03e809ba9a5075ecbac27bc3c3840f330171bcd2d68d
ep_bytes: 4883ec28e8a70400004883c428e97afe
timestamp: 2021-12-09 03:51:00

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0
InternalName: 加入任务计划
LegalCopyright: (C) 版权所有
OriginalFilename: 加入任务计划.exe
ProductName:
ProductVersion: 1.0
Translation: 0x0804 0x04b0

Trojan.Win32.Gasti.tm also known as:

LionicTrojan.Win32.Gasti.4!c
MicroWorld-eScanTrojan.GenericKD.38240074
McAfeeArtemis!61EFF768A47E
CylanceUnsafe
ZillyaTrojan.Gasti.Win32.136
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Gasti.b28f646c
K7GWRiskware ( 00584baa1 )
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Gasti.tm
BitDefenderTrojan.GenericKD.38240074
AvastWin64:TrojanX-gen [Trj]
TencentWin32.Trojan.Gasti.Wpjz
Ad-AwareTrojan.GenericKD.38240074
SophosGeneric ML PUA (PUA)
DrWebTrojan.Siggen16.3475
TrendMicroTROJ_GEN.R06BC0WLC21
FireEyeTrojan.GenericKD.38240074
EmsisoftTrojan.GenericKD.38240074 (B)
GDataTrojan.GenericKD.38240074
JiangminTrojan.Gasti.as
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D2477F4A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win.Generic.C4830366
VBA32Trojan.Gasti
ALYacTrojan.GenericKD.38240074
MAXmalware (ai score=84)
TrendMicro-HouseCallTROJ_GEN.R06BC0WLC21
RisingHackTool.NSSM!1.CABB (CLASSIC)
YandexTrojan.Gasti!KGQEGX8MGmc
MaxSecureTrojan.Malware.73803994.susgen
FortinetW32/PossibleThreat
AVGWin64:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Gasti.tm?

Trojan.Win32.Gasti.tm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment