Trojan

Trojan.Win32.Pasta.aodl malicious file

Malware Removal

The Trojan.Win32.Pasta.aodl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Pasta.aodl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Pasta.aodl?


File Info:

crc32: 27A6B239
md5: 87f768730de2d8dd1b1f69892bb2b5da
name: jbt.exe
sha1: 94be115cad2eb8c105f03e37d9af8350943a8923
sha256: a24e11c1a3c7467fff08d660e38f831881dca4760a986530ca38f25560e23074
sha512: 405f7e08b778c884ec150c894a1dfbc6122b75850040aa8a1d0a671c44a81db7cca2c91e94dc763684d700e5c739351f29b53e3c2255aa2286c92621a366a1e2
ssdeep: 393216:uBCU8clt/f+2WWbKhYugyDNNubV3UcmIe+Nz:uB7f+Ob2Y14ubVze+1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6377x8c79x901a x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x6377x8c79x901a
Comments: x4e13x4e1ax7834x5bc6x7801
ProductName: x6377x8c79x901a
ProductVersion: 1.0.0.0
FileDescription: x6377x8c79x901ax79d1x6280
Translation: 0x0804 0x04b0

Trojan.Win32.Pasta.aodl also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Trojan.StartPage.@t0@a49vhCoH
McAfeeArtemis!87F768730DE2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Trojan.StartPage.@t0@a49vhCoH
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.30de2d
BitDefenderThetaGen:NN.ZexaF.34108.@t0@a49vhCoH
F-ProtW32/Trojan.CLL.gen!Eldorado
APEXMalicious
GDataGen:Trojan.StartPage.@t0@a49vhCoH
KasperskyTrojan.Win32.Pasta.aodl
AlibabaTrojan:Win32/Pasta.746fa033
NANO-AntivirusTrojan.Win32.Pasta.ejybqd
TencentWin32.Trojan.Qqthief.Auto
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.StartPage.@t0@a49vhCoH (B)
ComodoWorm.Win32.Dropper.RA@1qraug
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.wc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.87f768730de2d8dd
SophosMal/Generic-S
IkarusVirus.Win32.OnLineGames
CyrenW32/Trojan.CLL.gen!Eldorado
JiangminTrojan.Pasta.abw
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Pasta
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.StartPage.EB534A
ZoneAlarmTrojan.Win32.Pasta.aodl
Acronissuspicious
VBA32Trojan.Pasta
ALYacGen:Trojan.StartPage.@t0@a49vhCoH
Ad-AwareGen:Trojan.StartPage.@t0@a49vhCoH
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
RisingTrojan.Pasta!8.106E (CLOUD)
YandexTrojan.Pasta!OvTyIAkDvG8
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/QQWare.A!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Pasta.aodl?

Trojan.Win32.Pasta.aodl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment