Trojan

Trojan:Win32/Azorult.DS!MTB removal tips

Malware Removal

The Trojan:Win32/Azorult.DS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.DS!MTB virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Azorult.DS!MTB?


File Info:

crc32: 19CA1B3A
md5: 1f859c62db008b2badbe5efda673fa01
name: mk.exe
sha1: 4eaa365fb3e9e1835122bda789f5648f93e31dcd
sha256: 1a57972053b2ceb2129bd033d7d5e77c49ae66429ce23ae0df485a18dddd24b5
sha512: 9327ad28bd52d1d68ad5b2204772a4cb2dd2b0740aeabd55d625eccadd50584d9e540398ebe23a97aaaccf69e8f9a32c238c0b0ad370ce49e64ae02909479c71
ssdeep: 12288:0A8KIqca3tj7co/ASPn2deK3T0d11buu5tcJcdBAVmizxNfxEk3Ycle8YrY:+KcCl7rP2ND8Luu5+6BAgizxlQrY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Azorult.DS!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.32576205
CAT-QuickHealTrojan.Multi
McAfeeFareit-FQC!1F859C62DB00
CylanceUnsafe
ZillyaTrojan.Injector.Win32.658996
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.32576205
K7GWTrojan ( 005594a91 )
K7AntiVirusTrojan ( 005594a91 )
Invinceaheuristic
CyrenW32/Injector.GPJK-1566
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EIFU
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Fareit-7331448-0
KasperskyHEUR:Trojan.Win32.Crypt.gen
AlibabaTrojan:Win32/Injector.f010c6b4
NANO-AntivirusTrojan.Win32.Crypt.gcpmtm
TencentMalware.Win32.Gencirc.10b88c63
Ad-AwareTrojan.GenericKD.32576205
EmsisoftTrojan.GenericKD.32576205 (B)
F-SecureTrojan.TR/AD.AgentTesla.frx
DrWebTrojan.PWS.Stealer.23680
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.LOKI.SMDD.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1f859c62db008b2b
SophosMal/Fareit-V
SentinelOneDFI – Suspicious PE
F-ProtW32/Injector.ILI
AviraTR/AD.AgentTesla.frx
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Crypt
MicrosoftTrojan:Win32/Azorult.DS!MTB
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F112CD
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
GDataTrojan.GenericKD.32576205
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34082.XGW@aGGvk@ai
ALYacSpyware.AgentTesla
VBA32TScope.Trojan.Delf
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMDD.hp
RisingTrojan.Injector!1.AFE3 (CLOUD)
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.EHDJ!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.fb3e9e
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ed1

How to remove Trojan:Win32/Azorult.DS!MTB?

Trojan:Win32/Azorult.DS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment