Trojan

Trojan.AzorultPMF.S25315702 removal instruction

Malware Removal

The Trojan.AzorultPMF.S25315702 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AzorultPMF.S25315702 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Nepali
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system

How to determine Trojan.AzorultPMF.S25315702?


File Info:

name: 69216227A70465115997.mlw
path: /opt/CAPEv2/storage/binaries/04f0df195e2e93372b63401ebd9d83c67613780f33a55da1efe8f35c9997bd10
crc32: 8E3FDAEA
md5: 69216227a70465115997a090bc39c3c3
sha1: d4041900d86775abf36894012af4b16cce70dec9
sha256: 04f0df195e2e93372b63401ebd9d83c67613780f33a55da1efe8f35c9997bd10
sha512: b67173d5566d23edc00a79cd6b169fc214bc146970535b6284424e39a51bede3ee1032fba2de1708c638fef2b6b31cdd0a2b8e7fa33fb96213dcaaf306e46731
ssdeep: 98304:O1cHOujotVU6nOl9j2jByn5CtO5Nxg2kNIa:O1cWUflxuBy5sO5MKa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D16334137E0C1B1E04518B64952CB7569BBF835873912CFBBD886B41B35BE1EA2A34F
sha3_384: fca132a5306807e7a096ed5066a061fd508065ea112881589da11ffa2b668277af0fbca8a80d409619f3caf88082f6e0
ep_bytes: e8db830000e978feffff8bff558bec83
timestamp: 2021-02-08 05:29:02

Version Info:

FileVers: 7.0.4.24
ProductVersa: 7.0.25.71
InternalName: reaLatimas
LegalCopyrighd: Jdfglsdffa
Translations: 0x0169 0x0301

Trojan.AzorultPMF.S25315702 also known as:

LionicTrojan.Win32.Fsysna.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.63207
MicroWorld-eScanTrojan.GenericKD.38197624
FireEyeGeneric.mg.69216227a7046511
CAT-QuickHealTrojan.AzorultPMF.S25315702
McAfeePacked-GBE!69216227A704
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3639186
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Azorult.a3602fc8
K7GWTrojan ( 0058b67e1 )
K7AntiVirusTrojan ( 0058b67e1 )
BitDefenderThetaGen:NN.ZexaF.34114.@t0@ayGEmbbG
CyrenW32/Kryptik.FXH.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HNOL
TrendMicro-HouseCallTROJ_GEN.R067C0DL721
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agent.pef
BitDefenderTrojan.GenericKD.38197624
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan.Kryptik.Wnwb
Ad-AwareTrojan.GenericKD.38197624
TACHYONTrojan/W32.Agent.4272128.T
SophosMal/Generic-S + Troj/Krypt-BO
Comodo.UnclassifiedMalware@0
TrendMicroTROJ_GEN.R067C0DL721
McAfee-GW-EditionBehavesLike.Win32.VirRansom.rc
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Azorult
GDataTrojan.GenericKD.38197624
JiangminTrojan.Fsysna.nme
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.yogns
Antiy-AVLTrojan/Generic.ASMalwS.34E6C92
GridinsoftRansom.Win32.AzorUlt.sa
ArcabitTrojan.Generic.D246D978
ViRobotTrojan.Win32.Z.Kryptik.4272128.A
MicrosoftTrojan:Win32/Azorult.RM!MTB
CynetMalicious (score: 99)
AhnLab-V3CoinMiner/Win.Glupteba.R456355
VBA32Malware-Cryptor.2LA.gen
ALYacTrojan.GenericKD.38197624
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!1.DAF8 (CLASSIC)
YandexTrojan.Fsysna!1LWzXSscFfk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HNOL!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.0d8677
PandaTrj/Genetic.gen

How to remove Trojan.AzorultPMF.S25315702?

Trojan.AzorultPMF.S25315702 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment