Trojan

Trojan:Win32/Astaroth!pz malicious file

Malware Removal

The Trojan:Win32/Astaroth!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Astaroth!pz virus can do?

  • Authenticode signature is invalid

How to determine Trojan:Win32/Astaroth!pz?


File Info:

name: 4042CD34FF56BD327EA1.mlw
path: /opt/CAPEv2/storage/binaries/7aa35fd8e2007a07ef445635eba7612364669f6a0430df72f4a3d45bc34510a5
crc32: 57B6C3EC
md5: 4042cd34ff56bd327ea13a29763360cc
sha1: 1813e4e9eb363b6f3a899b7b5fdccccba8653358
sha256: 7aa35fd8e2007a07ef445635eba7612364669f6a0430df72f4a3d45bc34510a5
sha512: d1a0f77906c03b20eeedfd48555cab0bd7173511bb9cf22b8a57bf43db1e6ddaa9c9c4603c1f188e6034b5187df57e5fd52f50f6dbf1c260ab20df4dc3be708f
ssdeep: 24:eH1GSw9APQeDR21SMwh0tYPFThtdCDIUovRidLYH/Lgz:yY1qQ1hWMStdCDapidcS
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T131712123A35644F3D6164F300F4B4D82E6FFD27A03B0441C0F0552183EA22A6E72AF49
sha3_384: b68684c291010d8d90da7c78bdab481bcbefdcf635ed4ac6b692beca160f32be380e913c2d884fd2dff9da40f5c3fd3b
ep_bytes: 558bec81c4f4feffff837d0c01755968
timestamp: 2011-07-06 19:58:41

Version Info:

0: [No Data]

Trojan:Win32/Astaroth!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Starter.ljdn
AVGWin32:GenMalicious-FOR [Trj]
MicroWorld-eScanGen:Variant.Zusy.208639
FireEyeGeneric.mg.4042cd34ff56bd32
CAT-QuickHealTrojan.Generic.19521
SkyhighW32/Ramnit.w
McAfeeW32/Ramnit.w
MalwarebytesTrojan.Runner
ZillyaTrojan.Genome.Win32.127201
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0000bf9e1 )
K7GWTrojan ( 0000bf9e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.36802.aq4@aiZYGOc
VirITTrojan.Win32.Starter.YY
SymantecTrojan.Bamital
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Ramnit.F
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Ramnit-7845
KasperskyTrojan.Win32.SuperThreat.d
BitDefenderGen:Variant.Zusy.208639
NANO-AntivirusTrojan.Win32.SuperThreat.csztyw
SUPERAntiSpywareTrojan.Agent/Gen-Ramnit
AvastWin32:GenMalicious-FOR [Trj]
TencentTrojan.Win32.Starter.a
TACHYONTrojan/W32.Starter.3584
SophosW32/Ramnit-BO
BaiduWin32.Trojan.Ramnit.d
F-SecureMalware.W32/Run.Ramnit.C
DrWebTrojan.Click2.2095
VIPREGen:Variant.Zusy.208639
TrendMicroTROJ_STARTER.SM
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.208639 (B)
IkarusTrojan.Rund
JiangminTrojan/Starter.if
WebrootW32.RamNit.Gen
VaristW32/Ramnit.E.gen!Eldorado
AviraW32/Run.Ramnit.C
Antiy-AVLVirus/Win32.Ramnit.f
KingsoftWin32.Troj.Agent.ac.3584
MicrosoftTrojan:Win32/Astaroth!pz
XcitiumTrojWare.Win32.Starter.ny@4m6u02
ArcabitTrojan.Zusy.D32EFF
ViRobotTrojan.Win32.Starter.3584.A
ZoneAlarmTrojan.Win32.SuperThreat.d
GDataGen:Variant.Zusy.208639
GoogleDetected
AhnLab-V3Trojan/Win32.Starter.R1831
Acronissuspicious
VBA32Trojan.SuperThreat
ALYacGen:Variant.Zusy.208639
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_STARTER.SM
RisingVirus.Ramnit!1.DDD7 (CLASSIC)
YandexTrojan.Starter!b8jAD0hXSqQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Ramnit.C!tr
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Ramnit.F

How to remove Trojan:Win32/Astaroth!pz?

Trojan:Win32/Astaroth!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment