Malware

How to remove “Troj/Azorult-EP”?

Malware Removal

The Troj/Azorult-EP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Azorult-EP virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Troj/Azorult-EP?


File Info:

crc32: 000496D8
md5: 4132b007d1e9a2b36f3d65171ec9991c
name: educrypted.exe
sha1: a430ef69abccffa3a8255b47e02a9148e4ce21d6
sha256: 6394166e1a1b81d6e9b2151ae59b368dc06817f5dc011569fcd711b729ab9023
sha512: 6280f67f474034d9ce5f06cf76913c88af9f53e999aca75df3c8a92f1d6b3f929fe31252828a61e3a44c815ef3efc0203c0f5ed451cfb3e83582a68a56530339
ssdeep: 6144:2HASPY4aGuMQrquDAYBycgtybzlrfzDQ4H:2gSPvarquDA+ycCClrrDt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Caxo 2020
Assembly Version: 2.0.0.0
InternalName: Caxo.exe
FileVersion: 2.0.0.0
CompanyName:
LegalTrademarks:
Comments: Caxo
ProductName:
ProductVersion: 2.0.0.0
FileDescription: Caxo
OriginalFilename: Caxo.exe

Troj/Azorult-EP also known as:

MicroWorld-eScanTrojan.GenericKD.43108243
FireEyeGeneric.mg.4132b007d1e9a2b3
ALYacTrojan.GenericKD.43108243
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005663a71 )
BitDefenderTrojan.GenericKD.43108243
K7GWTrojan ( 005663a71 )
Cybereasonmalicious.9abccf
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34108.wm0@aii78al
F-ProtW32/MSIL_Kryptik.AQN.gen!Eldorado
ESET-NOD32a variant of MSIL/GenKryptik.EJYW
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.43108243
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
AlibabaTrojan:MSIL/Bluteal.95764e05
RisingStealer.Azorult!8.11176 (CLOUD)
Ad-AwareTrojan.GenericKD.43108243
EmsisoftTrojan.GenericKD.43108243 (B)
ComodoMalware@#3aehmsan4rer2
F-SecureTrojan.TR/Kryptik.roobx
TrendMicroTROJ_FRS.VSNW06E20
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosTroj/Azorult-EP
IkarusTrojan.MSIL.Krypt
CyrenW32/MSIL_Kryptik.AQN.gen!Eldorado
JiangminTrojanSpy.MSIL.aplo
AviraTR/Kryptik.roobx
Antiy-AVLTrojan[Spy]/MSIL.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D291C793
AhnLab-V3Trojan/Win32.MSIL.R335940
ZoneAlarmHEUR:Trojan-Spy.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Bluteal.B!MTB
McAfeeRDN/Generic.grp
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.PCrypt.MSIL.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSNW06E20
TencentWin32.Trojan.Inject.Auto
SentinelOneDFI – Malicious PE
FortinetMSIL/GenKryptik.EJYW!tr
WebrootW32.Malware.Gen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.Spy.b3d

How to remove Troj/Azorult-EP?

Troj/Azorult-EP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment