Trojan

What is “Trojan-PSW.Win32.Azorult.akol”?

Malware Removal

The Trojan-PSW.Win32.Azorult.akol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Azorult.akol virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan-PSW.Win32.Azorult.akol?


File Info:

crc32: 4E25D701
md5: 40874a91259dc0a5e662f825b285cc91
name: buk.exe
sha1: 0cf54d7c5852c3157ce4dd278919cde76ab60f51
sha256: 74376c99984275f5c851bd88608f4507116fe49c9578497a9f8ebb94f85f2702
sha512: aef3fc8b7c3667f0aebf5caee297d73ee38f558f5568a3cf1000b7a8b2ad657e58ee3b61467589a33a9430b0410cbc3030f4a965ee41d4b36d732167aee5bb96
ssdeep: 24576:pu6J33O0c+JY5UZ+XC0kGso6Fa4M4zK/QmzYeSK3i9N2VJqtJkYsWY:Lu0c++OCvkGs9Fa41zK/QmzY5Ko2n07
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Azorult.akol also known as:

DrWebTrojan.AutoIt.709
MicroWorld-eScanTrojan.GenericKD.33030592
Qihoo-360Generic/HEUR/QVM10.2.00AF.Malware.Gen
McAfeeArtemis!40874A91259D
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33030592
Cybereasonmalicious.c5852c
Invinceaheuristic
CyrenW32/AutoIt.IJ.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Trojan-Stealer.Azorult.MTM2D6
KasperskyTrojan-PSW.Win32.Azorult.akol
AlibabaTrojan:Win32/Predator.cf611dba
RisingTrojan.Obfus/Autoit!1.C075 (CLASSIC)
Ad-AwareTrojan.GenericKD.33030592
SophosMal/Generic-S
F-SecureTrojan.TR/Autoit.rwrfs
TrendMicroTROJ_GEN.R002C0DB320
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.40874a91259dc0a5
EmsisoftTrojan.GenericKD.33030592 (B)
IkarusWin32.Outbreak
F-ProtW32/AutoIt.IJ.gen!Eldorado
AviraTR/Autoit.rwrfs
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F801C0
ZoneAlarmTrojan-PSW.Win32.Azorult.akol
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/AU3.Wacatac.S1079
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.AutoIt.Generic
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FAE
TrendMicro-HouseCallTROJ_GEN.R002C0DB320
TencentWin32.Trojan-qqpass.Qqrob.Pavn
FortinetAutoIt/Injector.EZY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Azorult.akol?

Trojan-PSW.Win32.Azorult.akol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment