Trojan

Trojan:Win32/Astaroth.psyW!MTB information

Malware Removal

The Trojan:Win32/Astaroth.psyW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Astaroth.psyW!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Astaroth.psyW!MTB?


File Info:

name: CBE4EFAF38D6B8EF6AB0.mlw
path: /opt/CAPEv2/storage/binaries/98a28edc958dff919bbbe4ff45790e503f426327b9d249ef9dcb903e4a508b49
crc32: 07FE4A72
md5: cbe4efaf38d6b8ef6ab0fdaab29746f8
sha1: 515b2409ce119812639a33ed21068d90764a9958
sha256: 98a28edc958dff919bbbe4ff45790e503f426327b9d249ef9dcb903e4a508b49
sha512: 6cee74f36aa055d169b0ede12562db3c8238c7b850ca71c00777ad84c09ac6ef93110ca8f6024ae698aeaac2e3797b619e956fb735be8e43e572f7f3c06f0ba7
ssdeep: 384:+ITiMV8WOY8Y9ygJ4oTbuAybGTfjuTakP:fTBkY8Y9lyMxjfWakP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E33E3382FD61AB6E377DAF385F696C6A935F432B902DA0D80CE0B450813F16AD91D1D
sha3_384: 8686a61a66d84a3dd041541a451fbfe33c7cf78eb9953ac75f358aa54f83e5b813a9d0f0d48d58a3abb9971cc00aedc9
ep_bytes: 558becb83c200000e8430300005633f6
timestamp: 2013-08-23 14:01:36

Version Info:

0: [No Data]

Trojan:Win32/Astaroth.psyW!MTB also known as:

BkavW32.AIDetectNet.01
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.CJOO
ClamAVWin.Downloader.Tiny-9940499-0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeUpatre-FAAI!CBE4EFAF38D6
VIPRETrojan.Agent.CJOO
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004546b61 )
K7GWTrojan-Downloader ( 004546b61 )
Cybereasonmalicious.f38d6b
VirITTrojan.Win32.DownLoader10.MQA
CyrenW32/Downloader.FKQY-3693
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Tiny.NIV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Agent.CJOO
NANO-AntivirusTrojan.Win32.Dwn.dikqpr
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Downloader-WID [Trj]
TencentTrojan-Downloader.Win32.Tiny.ha
EmsisoftTrojan.Agent.CJOO (B)
DrWebTrojan.DownLoader10.8528
ZillyaDownloader.Tiny.Win32.4156
TrendMicroTROJ_UPATRE.SMAZ
McAfee-GW-EditionBehavesLike.Win32.Upatre.qz
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.cbe4efaf38d6b8ef
SophosTroj/Upatre-XO
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.15D2QMU
JiangminTrojanDownloader.Generic.ampd
WebrootW32.Malware.Gen
AviraTR/ATRAPS.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
ArcabitTrojan.Agent.CJOO
ViRobotTrojan.Win32.Agent.35880
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/Astaroth.psyW!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R83549
VBA32Trojan.Downloader
ALYacTrojan.Agent.CJOO
Cylanceunsafe
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingDownloader.Waski!1.A489 (CLASSIC)
IkarusTrojan-Downloader.Win32.Tiny
MaxSecureDownloader.Upatre.a
FortinetW32/Tiny.NIV!tr
BitDefenderThetaGen:NN.ZexaF.36308.dmZ@a81Dcfi
AVGWin32:Downloader-WID [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Astaroth.psyW!MTB?

Trojan:Win32/Astaroth.psyW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment