Trojan

Trojan:Win32/Asruex.A removal instruction

Malware Removal

The Trojan:Win32/Asruex.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Asruex.A virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Asruex.A?


File Info:

crc32: AECCB9AF
md5: ecdb641a4d0de5125115a1cdcbb47e66
name: ECDB641A4D0DE5125115A1CDCBB47E66.mlw
sha1: 1333ef3c795e70c2807c155659ef5d5fd4c67075
sha256: c9eb9b940df8df5f4c0f68475a2670d40a5fb27b6b7da985977300f3f37a33a4
sha512: 7f1ffa984b0954778868f0b47191aa239f4eadee493a4dfea13feb91e61db2e043e7522dfe7148fa7764606f1806a3b259828918ecc8925a5485f2303181a264
ssdeep: 24576:KkIT2GNzn++GpF7usg5l7figQ5DXByXwUXw9n:ZITZznMFqsg5Q7DXBZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2015 Scooter Software, Inc.
FileVersion: 4.1.0
CompanyName: Scooter Software
LegalTrademarks: Beyond Compare xae is a registered trademark of Scooter Software, Inc.
Comments: Used to launch Beyond Compare from version control systems
ProductName: Beyond Compare
ProductVersion: 4.1
FileDescription: Beyond Compare launcher
OriginalFilename: BComp.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Asruex.A also known as:

BkavW32.FamVT.TaidoorY.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.356102
ALYacGen:Variant.Graftor.356102
CylanceUnsafe
ZillyaTrojan.Agent.Win32.689590
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001761171 )
BitDefenderGen:Variant.Graftor.356102
K7GWTrojan ( 001761171 )
CyrenW32/S-37d21855!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/Agent.RGR
APEXMalicious
ClamAVWin.Malware.Agentb-9808245-0
KasperskyTrojan.Win32.Agentb.bsps
NANO-AntivirusTrojan.Win32.Agent.ejpkdx
ViRobotTrojan.Win32.Agent.869376.I
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazpOqYppxA5P/bzw4BgKqk0z)
Ad-AwareGen:Variant.Graftor.356102
SophosML/PE-A + Troj/Mikey-B
ComodoTrojWare.Win32.Agent.RGRM@7jlyfw
F-SecureTrojan.TR/Crypt.XPACK.Gen4
DrWebTrojan.DownLoader21.55939
TrendMicroPE_ASRUEX.A
McAfee-GW-EditionGenericRXIQ-HA!ECDB641A4D0D
FireEyeGeneric.mg.ecdb641a4d0de512
EmsisoftGen:Variant.Graftor.356102 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.356102
JiangminTrojan.Agentb.biz
AviraTR/Crypt.XPACK.Gen4
GridinsoftTrojan.Win32.Agent.bot!s1
ArcabitTrojan.Graftor.D56F06
ZoneAlarmTrojan.Win32.Agentb.bsps
MicrosoftTrojan:Win32/Asruex.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agentb.R196717
Acronissuspicious
McAfeeGenericRXIQ-HA!ECDB641A4D0D
MAXmalware (ai score=84)
VBA32Trojan.Agentb
MalwarebytesBackdoor.Asruex
TrendMicro-HouseCallPE_ASRUEX.A
TencentMalware.Win32.Gencirc.10b8acda
YandexTrojan.GenAsa!kLLWd0Qcw70
IkarusTrojan.Win32.Agent
eGambitPE.Heur.InvalidSig
FortinetW32/Generic.AP.17284B2!tr
BitDefenderThetaGen:NN.ZexaF.34574.4u1@aKMDc8gi
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.a4d0de
AvastWin32:TrojanX-gen [Trj]
Qihoo-360HEUR/QVM10.2.0CBD.Malware.Gen

How to remove Trojan:Win32/Asruex.A?

Trojan:Win32/Asruex.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment