Trojan

Trojan-PSW.Win32.Azorult.aolo information

Malware Removal

The Trojan-PSW.Win32.Azorult.aolo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Azorult.aolo virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
bit.do
rebrand.ly
jamshed.pk
backgrounds.pk
karimgousa.ug
karimgouss.ug
colonna.ac.ug
colonna.ug

How to determine Trojan-PSW.Win32.Azorult.aolo?


File Info:

crc32: CFBF56B0
md5: 850238379a627b814613ef18869522a0
name: 850238379A627B814613EF18869522A0.mlw
sha1: f6d46c03e6ac255de864ace658db0c76cf1631c7
sha256: 863edc07e1ac0160bf2a1df6597b87038ccf2055fa4433d1e78fd0abfac6f74e
sha512: 79e472a24559ff3840c41675bce7db07833ad6d7d42126f9adde6a1ab0efc2f54fb3b8758abcbcb78fbd6870e6b2c8d5fb4dee5aa2ebbf8c9b3433f4df884f5f
ssdeep: 6144:hiW+V4+rOOhyYBvJwHIQV/fvkd3xMfysAoS:hiW+i+aOhlBujvkBxMGoS
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan-PSW.Win32.Azorult.aolo also known as:

K7AntiVirusBackdoor ( 00557edb1 )
LionicTrojan.Win32.Chapak.4!c
DrWebTrojan.Siggen9.55566
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Multi
ALYacGen:Variant.Razy.698093
CylanceUnsafe
ZillyaTrojan.Azorult.Win32.10
SangforTrojan.Win32.Ymacco.AA86
CrowdStrikewin/malicious_confidence_100% (W)
K7GWBackdoor ( 00557edb1 )
Cybereasonmalicious.79a627
CyrenW32/VB.SF.gen!Eldorado
SymantecInfostealer
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.VBGeneric-8264807-0
KasperskyTrojan-PSW.Win32.Azorult.aolo
BitDefenderGen:Variant.Razy.698093
NANO-AntivirusTrojan.Win32.Razy.hlkpnp
MicroWorld-eScanGen:Variant.Razy.698093
TencentMalware.Win32.Gencirc.10cdd799
Ad-AwareGen:Variant.Razy.698093
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#2hk8qeypqkoln
BitDefenderThetaGen:NN.ZexaF.34294.mmGfaOI0c2zi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Virut.cc
FireEyeGeneric.mg.850238379a627b81
EmsisoftGen:Variant.Razy.698093 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Multi.dd
WebrootW32.Trojan.Gen
AviraTR/Injector.xijdw
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.10558C2
MicrosoftTrojan:Win32/Ymacco.AA6F
GDataGen:Variant.Razy.698093
McAfeeArtemis!850238379A62
MAXmalware (ai score=87)
VBA32Trojan.Wacatac
RisingTrojan.Injector!1.C6AF (CLASSIC)
YandexTrojan.Injector!ixI/YyhZD1g
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ENLK!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Azorult.aolo?

Trojan-PSW.Win32.Azorult.aolo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment