Malware

What is “Troj/Azorult-FU”?

Malware Removal

The Troj/Azorult-FU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Azorult-FU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Troj/Azorult-FU?


File Info:

crc32: D6FF99FB
md5: b56d97ba158e3e81cfc1ed65376bf131
name: Bestellen Sie PC00056942.exe
sha1: 1085c68d0c9b26505dec4e81702009a92f531aa5
sha256: 8480058fc20ebfef47d1ebccbb54b88f656715b99c2d4e80ad46b05906ff4dbe
sha512: b89eaa6d5b137ef742c44bde8421c551af59ee986bc825a0f194d61026220c880cd1e0a01a73f5e0ce40d8a49cffab41c2394b40a15918c20b9c3aecc88d7a33
ssdeep: 12288:cgftlTxIDJRRtYRNeuawx2+8zVQLlcqPTxUHYY3UmNUS2FSLlCgTY4go5z2Gh:cg1JxIwP5YxaZ0dD6SfRCgTpgo5q8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Troj/Azorult-FU also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.29093
MicroWorld-eScanTrojan.GenericKD.34374041
FireEyeGeneric.mg.b56d97ba158e3e81
CAT-QuickHealTrojan.CKGENERIC
ALYacTrojan.GenericKD.34374041
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Kryptik.4!c
SangforMalware
K7AntiVirusTrojan ( 0056c99c1 )
BitDefenderTrojan.GenericKD.34374041
K7GWTrojan ( 0056c99c1 )
Cybereasonmalicious.d0c9b2
TrendMicroTROJ_GEN.R002C0DHI20
BitDefenderThetaGen:NN.ZelphiF.34196.TGW@a4gQIWii
CyrenW32/Injector.ORWQ-3620
SymantecInfostealer.Lokibot!43
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Keylogger.AgentTesla-9372622-1
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
NANO-AntivirusTrojan.Win32.Kryptik.hrmdcv
TencentWin32.Trojan.Kryptik.Pepp
Ad-AwareTrojan.GenericKD.34374041
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1121831
ZillyaTrojan.Injector.Win32.762513
Invinceaheuristic
SophosTroj/Azorult-FU
IkarusTrojan.Inject
JiangminTrojan.Kryptik.cbz
AviraHEUR/AGEN.1121831
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Fareit.VD!MTB
ArcabitTrojan.Generic.D20C8199
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataWin32.Trojan.PSE.8R1IYS
CynetMalicious (score: 100)
AhnLab-V3Suspicious/Win.Delphiless.X2091
Acronissuspicious
McAfeeFareit-FPQ!B56D97BA158E
MAXmalware (ai score=88)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.ENAI
TrendMicro-HouseCallTROJ_GEN.R002C0DHI20
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EMZL!tr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Trojan.469

How to remove Troj/Azorult-FU?

Troj/Azorult-FU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment