Trojan

What is “Trojan.Win32.Cutwail”?

Malware Removal

The Trojan.Win32.Cutwail is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cutwail virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Uzbek (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Win32.Cutwail?


File Info:

crc32: BBE214F5
md5: 7fc4870a54a69a822f35e8649a4e4d1b
name: 7FC4870A54A69A822F35E8649A4E4D1B.mlw
sha1: cdde513e55113d79df1c822cbff65ea77b17fa56
sha256: 30aa7971ca8a4000aaa7d284b102c4a5a3f4cbf734a1e90771e622f065ce3fdb
sha512: db66f80ed0fc0b4d0d0481ce1b66b7170d2e68afa4228af6d8f0a0dadeb9d28aefff36e8c1cd70535c44233da5019a37124404f073a1a56fd433656f6664f11a
ssdeep: 3072:pG34XWr5EPgQ98vy/OSDN0t7XvnlWvoQZFQiXJwOM8IUdQqRuxTJcIkC68ySKAb:c3fKPf9kcOSDN0BPlWv9jecQLOzCe7+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersions: 7.0.0.25
LegalCopyrights: Vsegda
ProductVersions: 67.0.20.45
Translation: 0x0409 0x0677

Trojan.Win32.Cutwail also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader36.42261
MicroWorld-eScanTrojan.GenericKD.45740456
CAT-QuickHealTrojan.Cutwail
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577faa1 )
BitDefenderTrojan.GenericKD.45740456
K7GWTrojan ( 00577faa1 )
BitDefenderThetaGen:NN.ZexaF.34574.pqW@aW6B6OgG
CyrenW32/Trojan.NCOQ-2309
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DBJ21
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Cutwail.gen
AlibabaTrojan:Win32/Azorult.bedd84fe
ViRobotTrojan.Win32.Z.Agent.258560.KI
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.45740456
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Cutwail.BF
ZillyaTrojan.Kryptik.Win32.2890785
TrendMicroTROJ_GEN.R002C0DBJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SentinelOneStatic AI – Suspicious PE
FireEyeGeneric.mg.7fc4870a54a69a82
EmsisoftTrojan.GenericKD.45740456 (B)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.Cutwail.BF
MicrosoftTrojan:Win32/Azorult.MX!MTB
GridinsoftTrojan.Win32.Kryptik.vb
ArcabitTrojan.Generic.D2B9F1A8
ZoneAlarmHEUR:Trojan.Win32.Cutwail.gen
GDataTrojan.GenericKD.45740456
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R366773
VBA32BScope.Trojan.Azorult
ALYacTrojan.GenericKD.45740456
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HJMB
eGambitUnsafe.AI_Score_68%
FortinetW32/Kryptik.HJNK!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Botnet.Cutwail.HwoCVWcA

How to remove Trojan.Win32.Cutwail?

Trojan.Win32.Cutwail removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment