Trojan

Trojan:Win32/Astaroth.psyH!MTB removal

Malware Removal

The Trojan:Win32/Astaroth.psyH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Astaroth.psyH!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Astaroth.psyH!MTB?


File Info:

name: 89C041A4AD73DD66DFD3.mlw
path: /opt/CAPEv2/storage/binaries/e9d4a861eb098a432c880e0db13c456c3f36841ad03604d71c4582ef07eb986c
crc32: 3A4C5E89
md5: 89c041a4ad73dd66dfd3c0fad1598640
sha1: 98fb5c0f7e053a9495c29a8b925a65b1f6cdb909
sha256: e9d4a861eb098a432c880e0db13c456c3f36841ad03604d71c4582ef07eb986c
sha512: 71585f68d5916b9ceeabc8716ba388a7f269e18fa3d68b954ae9b6c4a33bb405464e8a656f41c931311e1ca124fc12a02126f146717fc6e6e76b51e434e08486
ssdeep: 6144:Qg6Kb/4v76Vi12n6kE3hpgIVmlZmGfKte0TPduMW8ysa+CQ8vY3CP5u:ey/4v76ViAnqpXQlZmGfMe0TPbtk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A948D9AA892B0B1CF9424739094AF7882E7774D07DB8B7AD531CB347F99D8E521E01C
sha3_384: 1c45e4d8995e9d8db50f33d7398d72fe412c4716c42cb29836a6f38f45793724f436b0ee61b7e8a1038232eb6beccb09
ep_bytes: 00000000000000000000000000000000
timestamp: 1970-01-04 19:01:20

Version Info:

0: [No Data]

Trojan:Win32/Astaroth.psyH!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FakeAnti.4!c
MicroWorld-eScanTrojan.FakeAntivirus.Gen
ClamAVWin.Worm.Drolnux-9854861-0
FireEyeGeneric.mg.89c041a4ad73dd66
CAT-QuickHealWorm.Drolnux.S644909
ALYacTrojan.FakeAntivirus.Gen
MalwarebytesIbashade.Worm.Dropper.DDS
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005a3f041 )
AlibabaTrojan:Win32/Astaroth.b240c488
K7GWTrojan ( 005a3f041 )
Cybereasonmalicious.4ad73d
CyrenW32/Trojan.FXX.gen!Eldorado
SymantecTrojan.Toraldrop
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.NXFLCEF
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.FakeAntivirus.Gen
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Patched.Vsmw
EmsisoftTrojan.FakeAntivirus.Gen (B)
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Trojan.Kryptik.bio
VIPRETrojan.FakeAntivirus.Gen
TrendMicroTROJ_GEN.R03BC0CDJ23
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Astaroth
GDataTrojan.FakeAntivirus.Gen
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Astaroth
ArcabitTrojan.FakeAntivirus.Gen
MicrosoftTrojan:Win32/Astaroth.psyH!MTB
GoogleDetected
McAfeeGeneric-FAHD!89C041A4AD73
MAXmalware (ai score=84)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0CDJ23
RisingWorm.Ibashade!1.BC34 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Astaroth.psyH!MTB?

Trojan:Win32/Astaroth.psyH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment