Trojan

About “Trojan:Win32/Azorult.ER!MTB” infection

Malware Removal

The Trojan:Win32/Azorult.ER!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.ER!MTB virus can do?

  • Authenticode signature is invalid

How to determine Trojan:Win32/Azorult.ER!MTB?


File Info:

name: 0DAF3654B8754EC47F6D.mlw
path: /opt/CAPEv2/storage/binaries/11343a176cefff2bd2a428306194df1f899597d6fa5f27f6fc3f5608924ded3d
crc32: 9D823407
md5: 0daf3654b8754ec47f6d0b40215b6b33
sha1: 01d9768a6d5065b2d55ced98c70947f399208a52
sha256: 11343a176cefff2bd2a428306194df1f899597d6fa5f27f6fc3f5608924ded3d
sha512: 26c9a4afba8b604afc47220cbfc83968f1f3f8cbba258abb09c555f3c8f13c6055185b6c83044715213282dbe0c14d3f618f05534b700677a9baee147d9f1bd1
ssdeep: 6144:lQY5fsVSjD/hSM8Yq9quYcmAEwL2pboGutj3V/:z5UVGq9qzlutj3d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC547D90FAA190BAC1680070F27E37AF953D5A14171815D3B3EC56ACABF10E355FABD2
sha3_384: 08ae4bb14ab2dd73bb0be8764ebf0594e94e150297fab7ab51b7d03aaa0234688d254de88f3de136a8dacc1dbea3a98c
ep_bytes: e8ce050000e97afeffff558bec56ff75
timestamp: 2023-01-22 12:59:30

Version Info:

0: [No Data]

Trojan:Win32/Azorult.ER!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.GameHack.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.143295
SkyhighBehavesLike.Win32.RealProtect.dh
McAfeeArtemis!0DAF3654B875
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_90% (W)
K7GWUnwanted-Program ( 0059198d1 )
K7AntiVirusUnwanted-Program ( 0059198d1 )
ArcabitTrojan.Cerbu.D22FBF
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack_AGen.FI potentially unsafe
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Cerbu.143295
EmsisoftGen:Variant.Cerbu.143295 (B)
VIPREGen:Variant.Cerbu.143295
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.Krypt
Antiy-AVLRiskWare/Win32.Gamehack
MicrosoftTrojan:Win32/Azorult.ER!MTB
GDataGen:Variant.Cerbu.143295
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4997316
ALYacGen:Variant.Cerbu.143295
VBA32BScope.TrojanPSW.Disco
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:1zMoqQ8/XLtikikc7+BB0g)
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/GameHack_AGen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Azorult.ER!MTB?

Trojan:Win32/Azorult.ER!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment