Trojan

Trojan:Win32/Astaroth.psyY!MTB removal

Malware Removal

The Trojan:Win32/Astaroth.psyY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Astaroth.psyY!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Astaroth.psyY!MTB?


File Info:

name: 29B9F0CEA866982485F7.mlw
path: /opt/CAPEv2/storage/binaries/f7188b09e993b7b9cd26c7999e710c48ea288a2bc450d42e3dd0eee51df27f89
crc32: CD1DC747
md5: 29b9f0cea866982485f7f958c8f3ebe5
sha1: e9f4a6fdeab70760e5462ea9efd0db1f7678a770
sha256: f7188b09e993b7b9cd26c7999e710c48ea288a2bc450d42e3dd0eee51df27f89
sha512: a92acaba36a83123bb33e484510d7a776ca5749f18b700412c5e6bea6aba290ea0e5743fd1acd713a460627144670feb1c7471682ca8685f18000339e55751fc
ssdeep: 196608:QiZfGMkASVqV26hgDneSclXOV0r+KG0lecQTuneUV/pVrIDLwp:/uMkqE54rcYQHUhpVkDLwp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18196DF3A6BC2A6CDD4CDE3785AD9CE24BD161FF89387BEC1F39684264123275620607D
sha3_384: 131e2e706bd8f2c7d7696529729f9f05fa6cd395bb37e95abd33fff8700ab9cae3dd54916d666976780e7e2af37e2c24
ep_bytes: 558bec6aff68f8204000685018400064
timestamp: 2012-08-29 06:22:26

Version Info:

Comments:
CompanyName: SafeNet, Inc.
FileDescription: For use with any SafeNet hardware security device.
FileVersion: 7.1.0
InternalName: setup.exe
OriginalFilename: setup.exe
LegalCopyright: Copyright 2005 Safenet, Inc.
ProductName: Sentinel Protection Installer 7.1.0
ProductVersion: 7.1.0
Translation: 0x0409 0x04e4

Trojan:Win32/Astaroth.psyY!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.364336
ClamAVWin.Malware.Bzub-9969513-0
FireEyeGeneric.mg.29b9f0cea8669824
CAT-QuickHealTrojanToga.MUE.R9
McAfeePWSZbot-FIB!29B9F0CEA866
ZillyaBackdoor.Androm.Win32.83443
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003dc1641 )
K7GWTrojan ( 003dc1641 )
Cybereasonmalicious.ea8669
BaiduWin32.Trojan-Dropper.Injector.f
SymantecW32.Faedevour!inf
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PYF
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.qxe
BitDefenderGen:Variant.Barys.364336
NANO-AntivirusTrojan.Win32.Androm.ctymsi
AvastWin32:Zbot-THZ [Trj]
TencentBackdoor.Win32.Androm.qxe
EmsisoftGen:Variant.Barys.364336 (B)
DrWebTrojan.Inject2.58694
VIPREGen:Variant.Barys.364336
McAfee-GW-EditionPWSZbot-FIB!29B9F0CEA866
Trapminemalicious.high.ml.score
SophosTroj/Mdrop-JIJ
IkarusBackdoor.Win32.Androm
GDataWin32.Trojan.PSE.10YPZ2S
JiangminTrojanDropper.Daws.byh
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Androm.qxe
XcitiumTrojWare.Win32.Toga.PYF@7g9q1h
ArcabitTrojan.Barys.D58F30
ViRobotWin32.Daws.B
MicrosoftTrojan:Win32/Astaroth.psyY!MTB
GoogleDetected
AhnLab-V3Backdoor/Win.Androm.C5366224
ALYacGen:Variant.Barys.364336
MAXmalware (ai score=86)
VBA32BScope.Trojan.Autoit
Cylanceunsafe
RisingDropper.Agent!1.AF79 (CLASSIC)
YandexTrojan.GenAsa!zFH4sqyAwHU
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.AQV!tr
AVGWin32:Zbot-THZ [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan:Win32/Astaroth.psyY!MTB?

Trojan:Win32/Astaroth.psyY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment