Trojan

TrojanDownloader:Win32/Cutwail.BT malicious file

Malware Removal

The TrojanDownloader:Win32/Cutwail.BT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Cutwail.BT virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

admin.stock-soft.com

How to determine TrojanDownloader:Win32/Cutwail.BT?


File Info:

crc32: 491104B8
md5: 0b7b2f450c91233913adbe119eb0c354
name: 0B7B2F450C91233913ADBE119EB0C354.mlw
sha1: 87acaf5833a8c42476d1801ce8f83d7a8675a567
sha256: f8f32273dc61db9a1140684be611167f9c7cab9dcb4207e504e205c5c3d10d13
sha512: 515938294d92793e1c9909071e820c38a1260f4a3c8c9c39b5fe2d83e496504c8f83baacb9c9537221533614a137655a0fe1bef1457f97d6ce8cb8041861d0c6
ssdeep: 384:hukPud1HaGIe9moa1sUl/dk5wU8Ggtah91Mcn+4H837Qi95IR+QJ:c4uLE1s2iGhah9tE7l95IR+W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Cutwail.BT also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.JP.buX@auWc7Vci
FireEyeGeneric.mg.0b7b2f450c912339
McAfeeDownloader-FAKG!0B7B2F450C91
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Cutwail.bw (v)
AegisLabTrojan.Win32.Generic.lrhh
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Trojan.Heur.JP.buX@auWc7Vci
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Dropper-gen [Drp]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Bulknet.vktrc
ViRobotTrojan.Win32.Jorik.20920
RisingDownloader.Cutwail!8.670 (TFE:4:myXta1v8RrE)
Ad-AwareGen:Trojan.Heur.JP.buX@auWc7Vci
SophosMal/Generic-S
ComodoTrojWare.Win32.Kryptik.AIJE@4q3exi
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.Bulknet.546
ZillyaTrojan.Jorik.Win32.114031
TrendMicroMal_Pushdo-1
McAfee-GW-EditionDownloader-FAKG!0B7B2F450C91
EmsisoftGen:Trojan.Heur.JP.buX@auWc7Vci (B)
IkarusTrojan.Win32.Jorik
JiangminTrojan/Jorik.eebp
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Totem
KingsoftWin32.Troj.Jorik.rm.(kcloud)
MicrosoftTrojanDownloader:Win32/Cutwail.BT
ArcabitTrojan.Heur.JP.EFC475
SUPERAntiSpywareTrojan.Agent/Gen-Jorik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.JP.buX@auWc7Vci
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R32442
Acronissuspicious
BitDefenderThetaAI:Packer.8265A3B61F
ALYacGen:Trojan.Heur.JP.buX@auWc7Vci
TACHYONTrojan/W32.Jorik.20992.B
VBA32Trojan.Totem
MalwarebytesRansom.Agent.Generic
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.AHXV
TrendMicro-HouseCallMal_Pushdo-1
TencentMalware.Win32.Gencirc.114b55af
YandexTrojan.GenAsa!bGxqFxm3ZiY
SentinelOneStatic AI – Suspicious PE
FortinetW32/CutMail.EE!tr
WebrootW32.Rogue.Gen
AVGWin32:Dropper-gen [Drp]
Cybereasonmalicious.50c912
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM19.Gen

How to remove TrojanDownloader:Win32/Cutwail.BT?

TrojanDownloader:Win32/Cutwail.BT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment