Trojan

What is “Trojan:Win32/Astaroth!pz”?

Malware Removal

The Trojan:Win32/Astaroth!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Astaroth!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Astaroth!pz?


File Info:

name: D3B9DFC342CB50E4D0ED.mlw
path: /opt/CAPEv2/storage/binaries/4653be95ca226c0f51eca6660b92576a173369ecef41d8bc1822c75b7f2e4330
crc32: 43E06186
md5: d3b9dfc342cb50e4d0ed512cf25df771
sha1: be53b62daf1a726d3e7764b0538f54b733e3c47a
sha256: 4653be95ca226c0f51eca6660b92576a173369ecef41d8bc1822c75b7f2e4330
sha512: 24c19f2c15b01e5675df79a4b517cd1c6362be4c53ebbcaf34bbbbaf083848f44ae8bd748603efdc67d83b45e9f8d3e613a52f935a0e1581f043cc63b96ec6ee
ssdeep: 49152:JaCpS2+aRFQV9uh+cO0STnmiNo2TFyRGCWHvHpQ9fy6+inv31svLKXFr7fRW1K83:xpn+sQV8+cO0STnmiN9TFy0TQk6+invY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12EE5BF617750C03BC27F31318AAABB74B6BADD305D3542472BA57F396E70852992832F
sha3_384: 11775f7cfee0a418ffec11ca3e8a063187593d6d48ddce3a41dc10504d8cf184cdc80044f81db3bb818fa0c244633dc5
ep_bytes: 558bec6aff68f8204000685018400064
timestamp: 2012-08-29 06:22:26

Version Info:

CompanyName: Corel Corporation
FileDescription: Corel Installation Program
FileVersion: 3.0.1.804
LegalCopyright: Copyright (C) 2010 Corel Corporation. All rights reserved.
ProductName: Corel Setup Engine
ProductVersion: 3.0.1.804
CompileDate: Saturday, November 24, 2012 10:10 PM
Translation: 0x0409 0x04e4

Trojan:Win32/Astaroth!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Barys.322939
CAT-QuickHealTrojanToga.MUE.R9
SkyhighPWSZbot-FIB!D3B9DFC342CB
McAfeePWSZbot-FIB!D3B9DFC342CB
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.322939
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003dc1641 )
K7GWTrojan ( 003dc1641 )
Cybereasonmalicious.342cb5
BaiduWin32.Trojan-Dropper.Injector.f
SymantecW32.Faedevour!inf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PYF
APEXMalicious
ClamAVWin.Malware.Bzub-9969513-0
KasperskyBackdoor.Win32.Androm.qxe
BitDefenderGen:Variant.Barys.322939
NANO-AntivirusTrojan.Win32.Androm.ctymsi
AvastWin32:Zbot-THZ [Trj]
TencentBackdoor.Win32.Androm.qxe
EmsisoftGen:Variant.Barys.322939 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Inject2.58694
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d3b9dfc342cb50e4
SophosInjector-JDW (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.qcz
VaristW32/S-24f4c04b!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/Win32.Androm.qxe
MicrosoftTrojan:Win32/Astaroth!pz
XcitiumTrojWare.Win32.Toga.PYF@7g9q1h
ArcabitTrojan.Barys.D4ED7B
ViRobotWin32.Daws.B
ZoneAlarmBackdoor.Win32.Androm.qxe
GDataWin32.Trojan.PSE.10YPZ2S
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.36802.@w3@a0Ql2wyT
ALYacGen:Variant.Barys.322939
VBA32BScope.Trojan.Autoit
Cylanceunsafe
RisingDropper.Agent!1.AF79 (CLASSIC)
YandexTrojan.GenAsa!zFH4sqyAwHU
IkarusBackdoor.Win32.Androm
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.PYF!tr
AVGWin32:Zbot-THZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudVirTool:Win/SignThief.A(dyn)

How to remove Trojan:Win32/Astaroth!pz?

Trojan:Win32/Astaroth!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment