Trojan

Trojan:Win32/Gamaredon.psyU!MTB removal instruction

Malware Removal

The Trojan:Win32/Gamaredon.psyU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gamaredon.psyU!MTB virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Gamaredon.psyU!MTB?


File Info:

name: 1F4970C2709FF6E9AD58.mlw
path: /opt/CAPEv2/storage/binaries/e31549eb9d5e5f3a9ac7d147de81c79050f87d7d77656cf35839a4ea1b8c9d8d
crc32: ACE73BFF
md5: 1f4970c2709ff6e9ad58d79e9f141374
sha1: a1f526fa8235cc433e98f7625e7e648ed4e44a01
sha256: e31549eb9d5e5f3a9ac7d147de81c79050f87d7d77656cf35839a4ea1b8c9d8d
sha512: b171d2676c6d20573bcb89524c03e1a9f488a9166efb9c274e86dba7bd6a9f76e6bd65e76d9f5253dfe0b1d1dd36c8aa3772e9e214b945c4c502eddba22861d4
ssdeep: 12288:XUzmqOeHkziCiqh5IlBdlOmyIWiOavGyIWS+amA7O1zquLX9kkk99XX9+miK4Psz:XUCqwi10IlO7OUN+DPslzbjbelQrnp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD252A3B778E9936DC3218BC4D8FE1A1A45A36742C189E93F7D09F4D5E34181372A98B
sha3_384: 7c5495d7a0cf5140ae4fe36d96f32d650be3d921594ef1cc0a26bd01ba2ca4394de180598300a46905b9a324804bab90
ep_bytes: 558bec83c4f05356b87c6c4e00e86601
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.37
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0416 0x04e4

Trojan:Win32/Gamaredon.psyU!MTB also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.440160
ClamAVWin.Trojan.Netmail-9844910-0
FireEyeGeneric.mg.1f4970c2709ff6e9
CAT-QuickHealTrojan.Dorv.9812
ALYacGen:Variant.Zusy.440160
MalwarebytesGeneric.Trojan.Delf.DDS
VIPREGen:Variant.Zusy.440160
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059c1621 )
K7GWTrojan ( 0059c1621 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.CLMX
CyrenW32/Banker.V.gen!Eldorado
SymantecInfostealer.Bancos!g5
ESET-NOD32a variant of Win32/Spy.Banker.WGA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.kkoq
BitDefenderGen:Variant.Zusy.440160
NANO-AntivirusTrojan.Win32.FakeAV.drrvw
AvastWin32:BankerX-gen [Trj]
TencentTrojan-Ransom.Win32.Blocker.he
SophosTroj/Banker-GYO
DrWebTrojan.DownLoader4.51703
ZillyaTrojan.FakeAV.Win32.109581
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.fh
EmsisoftGen:Variant.Zusy.440160 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Stealer.Banker.AK
AviraDR/Delphi.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FakeAV
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
ArcabitTrojan.Zusy.D6B760
ZoneAlarmTrojan-Ransom.Win32.Blocker.kkoq
MicrosoftTrojan:Win32/Gamaredon.psyU!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Agent.R554978
McAfeePWS-Banker.gen.ez
TACHYONTrojan/W32.DP-Agent.1044992.C
VBA32BScope.Trojan.Downloader
Cylanceunsafe
TrendMicro-HouseCallRansom_Blocker.R03BC0DC123
RisingRansom.Agent!8.6B7 (TFE:5:Ku0xTvM8GaG)
YandexTrojan.FakeAV!WsJ4kBJx68o
IkarusTrojan-Banker.Win32.Delf
FortinetW32/Banker.WGA!tr
BitDefenderThetaGen:NN.ZelphiF.36308.@G0@ai1z35iG
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.2709ff
PandaGeneric Malware

How to remove Trojan:Win32/Gamaredon.psyU!MTB?

Trojan:Win32/Gamaredon.psyU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment