Malware

About “Troj/Azorult-EC” infection

Malware Removal

The Troj/Azorult-EC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Azorult-EC virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Troj/Azorult-EC?


File Info:

crc32: 2B6B073A
md5: 5c0a365f9152162e2662766b0beb1979
name: mecrutoo.exe
sha1: d856e79f68f03e91045377ac92b6f8356d135170
sha256: 167cef6fd61eec938ab15b0f40e66e5c197a4dd44fc9f9a534ddc283f1134a3b
sha512: 0daa9037393aaea10529e55309967e6e5d1aee418303c4f7be1d69555bf00acbe41d8d0e6e59feafcb508500db710bcc7f26f6cefecd959b2998991519bf7d04
ssdeep: 3072:eSiXAwar2KkqPFXSUjoMYHcXpAHO/YrLw8/LppbQEfZ5wC:cXXar2dwhSoMHc5v/Y3w8BZ5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: 2.1r2, xa9 2000-2005 Maxprog
InternalName:
FileVersion: 2.1..2
CompanyName:
Country:
ProductName:
ProductVersion: 2.1r2
FileDescription: eMail Extractor v2.1r2
Release: Final
OriginalFilename: eMail Extractor.exe

Troj/Azorult-EC also known as:

MicroWorld-eScanTrojan.GenericKD.42858921
Qihoo-360Generic/Trojan.PSW.a72
McAfeePacked-FWY!5C0A365F9152
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.42858921
K7GWTrojan ( 0056081c1 )
K7AntiVirusTrojan ( 0056081c1 )
ArcabitTrojan.Generic.D28DF9A9
TrendMicroTROJ_GEN.R002C0PCI20
F-ProtW32/MSIL_Kryptik.AIU.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Kryptik.VCR
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Azorult.gen
AlibabaTrojan:Win32/csharp.ali2000008
Ad-AwareTrojan.GenericKD.42858921
EmsisoftTrojan.Crypt (A)
F-SecureHeuristic.HEUR/AGEN.1002951
DrWebTrojan.Siggen9.22017
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
FortinetMSIL/0131.A!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5c0a365f9152162e
SophosTroj/Azorult-EC
IkarusTrojan.MSIL.Inject
CyrenW32/MSIL_Kryptik.AIU.gen!Eldorado
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1002951
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan-PSW.MSIL.Azorult.gen
AhnLab-V3Trojan/Win32.Agent.R284273
Acronissuspicious
ALYacSpyware.Infostealer.Azorult
MalwarebytesTrojan.HCrypt.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PCI20
RisingStealer.Azorult!8.11176 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_72%
GDataTrojan.GenericKD.42858921
BitDefenderThetaGen:NN.ZemsilF.34100.Gm0@aC1PL2Ai
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f68f03
AvastWin32:TrojanX-gen [Trj]

How to remove Troj/Azorult-EC?

Troj/Azorult-EC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment