Malware

PWS:Win32/Azorult.V!MTB removal

Malware Removal

The PWS:Win32/Azorult.V!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Azorult.V!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:Win32/Azorult.V!MTB?


File Info:

crc32: 12E44765
md5: b4bf3dd0b414349b3325609274b54678
name: socks111atx.exe
sha1: 70f3706204dfca0649648e5becb27b794250d7d7
sha256: e99a270e42423cfc57b8f0c7700dc3db63bfb0e8252abd118da000c112935b4e
sha512: 813801f66c9d972d8b2a3fb2451be0d3e0dd4e9e185a75fb45bc4dbedd5109d1506657bca3059010d7b2384a62b33ef7d984bbc63a2890bedffd254be68f8ed6
ssdeep: 6144:2rjuBFRIf41UxBGaBZ4Mk7Jb/rddfi77+BG:sKFREBGKZBk7JbBdYi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0115 0x04e5

PWS:Win32/Azorult.V!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.32903402
McAfeeGenericRXJK-EQ!B4BF3DD0B414
BitDefenderTrojan.GenericKD.32903402
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GZYT
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Zenpak.vho
RisingTrojan.Generic@ML.90 (RDML:MyGUzkRKEvieTvv7BFb1Ow)
Ad-AwareTrojan.GenericKD.32903402
EmsisoftTrojan.GenericKD.32903402 (B)
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.dh
FireEyeGeneric.mg.b4bf3dd0b414349b
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojan.Propagate.bus
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F610EA
ZoneAlarmHEUR:Trojan.Win32.Zenpak.vho
MicrosoftPWS:Win32/Azorult.V!MTB
AhnLab-V3Trojan/Win32.MalPe.R306780
Acronissuspicious
ALYacTrojan.GenericKD.32903402
MAXmalware (ai score=80)
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_98%
GDataTrojan.GenericKD.32903402
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.0ea

How to remove PWS:Win32/Azorult.V!MTB?

PWS:Win32/Azorult.V!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment