Trojan

Trojan:Win32/Aksula!pz (file analysis)

Malware Removal

The Trojan:Win32/Aksula!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Aksula!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Aksula!pz?


File Info:

name: 475EE5C8EAD77D646C00.mlw
path: /opt/CAPEv2/storage/binaries/30ebea7f7d3118fc2c937ba595b563516c0ae2fd7060d8c109131efe878cc8d2
crc32: F496E5F0
md5: 475ee5c8ead77d646c001d38616d0a16
sha1: 468e42d4a182741bf97fd77b8568705c16f495c9
sha256: 30ebea7f7d3118fc2c937ba595b563516c0ae2fd7060d8c109131efe878cc8d2
sha512: d8eaf476976f599ee93c3572420c8effb808a239a3199afd3179ce8f3e22d7c6908a74c99947c5f9160d5d0855b1ab886efc5c06ec7511289d690602e1629384
ssdeep: 768:MS2ZWDhMgJFo7LDc+LAfh7hC145SC145:MSrdzo7vc+LAp7Qq5q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18AD29F5183C84920C5690F7559968BB6F33BAE804B15CB8B0C8B7F1F5DBA1239A63563
sha3_384: 11bc9b5cd7d3a1c1ea33d72f792bff59c495b756f3134c50d66663031eb624de905c3a8213a6d4cba8b1e6f7d55cf387
ep_bytes: 4a4afb003d3df9427272fbf7c1c1fdfa
timestamp: 2011-02-16 18:58:04

Version Info:

0: [No Data]

Trojan:Win32/Aksula!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.mew1
MicroWorld-eScanGen:Variant.Razy.603545
FireEyeGeneric.mg.475ee5c8ead77d64
SkyhighBehavesLike.Win32.Generic.nh
McAfeeGenericRXAA-AA!475EE5C8EAD7
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Vindor.0c51d102
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.36792.bmW@aSNkZen
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Razy.603545
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Razy.603545 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
VIPREGen:Variant.Razy.603545
TrendMicroTROJ_GEN.R002C0DJJ23
Trapminemalicious.high.ml.score
SophosMal/HckPk-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.603545
VaristW32/ABRisk.GHWG-3888
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Vindor
Kingsoftmalware.kb.b.981
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Razy.D93599
MicrosoftTrojan:Win32/Aksula!pz
GoogleDetected
AhnLab-V3Trojan/Win.Agent.R613930
ALYacGen:Variant.Razy.603545
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DJJ23
RisingTrojan.Vindor!8.10CC (CLOUD)
IkarusTrojan.Win32.Agent
MaxSecureVirus.Patched.OF
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.4a1827
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Aksula!pz?

Trojan:Win32/Aksula!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment