Trojan

Should I remove “Trojan-PSW.Win32.Azorult.aldq”?

Malware Removal

The Trojan-PSW.Win32.Azorult.aldq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Azorult.aldq virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan-PSW.Win32.Azorult.aldq?


File Info:

crc32: 32391145
md5: 7e5e94bbb33209749d104bae7406c900
name: bz.exe
sha1: 675b49433a69aad512397c06bb654ce9c81f01fb
sha256: cbf2c9263616a8209e2b82155392784bab933c7148361a7996bb553a0eb900e0
sha512: e83bf8009e120920403c379485ceb804db50ed550b58efba5e53e5858f8368eaf9af75ce314f69ab4988b8baf8ea59b5bc13f7c7699aeb4e0d14ad4da7a31b38
ssdeep: 24576:oAHnh+eWsN3skA4RV1Hom2KXSmdafpFNS6dw8tAze6FBnCUtj5:vh+ZkldoPKi2afnezFBnCi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Azorult.aldq also known as:

MicroWorld-eScanAIT:Trojan.Nymeria.2968
FireEyeGeneric.mg.7e5e94bbb3320974
Qihoo-360Win32/Trojan.PSW.5cd
McAfeeArtemis!7E5E94BBB332
CylanceUnsafe
AegisLabTrojan.Win32.Nymeria.4!c
SangforMalware
K7AntiVirusTrojan ( 005604201 )
BitDefenderAIT:Trojan.Nymeria.2968
K7GWTrojan ( 005604201 )
Cybereasonmalicious.33a69a
Invinceaheuristic
F-ProtW32/Autoit.G.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.FBN
APEXMalicious
AvastWin32:Malware-gen
GDataAIT:Trojan.Nymeria.2968
KasperskyTrojan-PSW.Win32.Azorult.aldq
AlibabaTrojan:Win32/Predator.ce855617
TencentWin32.Trojan.Agent.Auto
EmsisoftAIT:Trojan.Nymeria.2968 (B)
F-SecureTrojan.TR/AD.MoksSteal.mnahj
TrendMicroTROJ_GEN.R020C0TBA20
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.HawkEye
CyrenW32/Autoit.G.gen!Eldorado
WebrootW32.Trojan.Nymeria
AviraTR/AD.MoksSteal.mnahj
Endgamemalicious (high confidence)
ArcabitAIT:Trojan.Nymeria.DB98
ZoneAlarmTrojan-PSW.Win32.Azorult.aldq
MicrosoftTrojan:Win32/Predator.BC!MTB
AhnLab-V3Trojan/AU3.Wacatac.S1079
Acronissuspicious
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.AutoIt
TrendMicro-HouseCallTROJ_GEN.R020C0TBA20
RisingTrojan.Obfus/Autoit!1.C075 (CLASSIC)
YandexTrojan.AvsArher.bS9LKk
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Injector.EZY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Azorult.aldq?

Trojan-PSW.Win32.Azorult.aldq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment