Trojan

Trojan.Win32.AddUser.asx removal tips

Malware Removal

The Trojan.Win32.AddUser.asx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AddUser.asx virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.AddUser.asx?


File Info:

name: B2FD9E3C1183957B1F86.mlw
path: /opt/CAPEv2/storage/binaries/565f0a91d19116f043f6a104cec98089f6838e33994f5ebf79ddf8f4a57b1332
crc32: 93A8241F
md5: b2fd9e3c1183957b1f861f02fee2fd57
sha1: 89f3d9a007a5b77ebf257a20eeca1abb074de1d4
sha256: 565f0a91d19116f043f6a104cec98089f6838e33994f5ebf79ddf8f4a57b1332
sha512: c0d2b7167da6e6dc2e860bb04355b28cd1ad8f770aaf9093b9bffe9b152a19d2561d849b110c7af97f1c0107beace220ad5aded37f76d4a572035f1ce01fa40b
ssdeep: 12288:xRMQu/0XFVeQrlH+6qnOI2KZNZ94JW6UHDlaD10ZvuDBZy8CWgeYBg6fC2hIpw:O/01BU6qnOZgAWhjlgaeBZy8CTeugoh5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194F4CE3E5E9A8B93E1A1C3B40FA77731D9D8DA8AF8D41653E3C8E4C77A251393887114
sha3_384: bc9e6b030fd2b2c07310b7a4caa355911eaa2a936be0a6b84f4c0d78cbdf3ea9e89cb9e504618969a6826bd36a549c23
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 子凌的处女作品
ProductName: 子凌专用多功能记事本
ProductVersion: 1.0.0.0
CompanyName: 子凌
LegalCopyright: 希望和喜欢易语言的交流~ QQ:172208538
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.Win32.AddUser.asx also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Nimnul.lUSv
tehtrisGeneric.Malware
ClamAVWin.Trojan.ASP-12
McAfeeArtemis!B2FD9E3C1183
MalwarebytesTrojan.FlyStudio
ZillyaTrojan.AddUser.Win32.900
SangforTrojan.Win32.Adduser.Vvap
K7AntiVirusTrojan ( 005194cc1 )
K7GWTrojan ( 005194cc1 )
Cybereasonmalicious.007a5b
VirITTrojan.Win32.Click2.DFZZ
CyrenW32/S-759a1e41!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.AddUser.asx
NANO-AntivirusTrojan.Win32.AddUser.jzondy
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13ee0dc6
F-SecureTrojan.TR/Agent.rapkt
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b2fd9e3c1183957b
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.AddUser.eq
Webroot
AviraTR/Agent.rapkt
Kingsoftmalware.kb.a.927
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
ZoneAlarmTrojan.Win32.AddUser.asx
GDataWin32.Riskware.FlyStudio.C
GoogleDetected
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07HQ23
RisingTrojan.AddUser!8.E12 (CLOUD)
IkarusVirus.Win32.Parite
MaxSecureVirus.W32.Flystudio.Y
FortinetW32/FlyStudio.C!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.AddUser.asx?

Trojan.Win32.AddUser.asx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment