Trojan

Trojan:Win32/Azorult.NC!MTB removal instruction

Malware Removal

The Trojan:Win32/Azorult.NC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.NC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Persian (Iran)
  • Unconventionial language used in binary resources: Tamil
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Anomalous binary characteristics

How to determine Trojan:Win32/Azorult.NC!MTB?


File Info:

crc32: 0E139FD2
md5: 5ed271e10ba37319d01d44acd33489a7
name: 5ED271E10BA37319D01D44ACD33489A7.mlw
sha1: 7130a850b50d5fccc1401f57ad95cac863a02062
sha256: 178fb69c394a6d86a3695acbb025bc2f3be31dea683ee6e5016af0566eef8111
sha512: 882d1adf9f2513d5578a72dcc50f0ef510def30c2c1ed0af5f051752e299a72be79c48660038aa852a39007c8286c6ea2ba2886cf0d8e4a859573faedf1ca27f
ssdeep: 6144:p1fScdMZ+ZaBOwGhLYZnVaGf3aOB3JZAI7:p1K8MZ+ZaZGhLYvaW3asZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calimarimodunador.exe
FileVersions: 7.0.1.53
LegalCopyrights: Vsekdar
ProductVersions: 67.0.21.45
Translation: 0x0429 0x04eb

Trojan:Win32/Azorult.NC!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.79843
FireEyeGeneric.mg.5ed271e10ba37319
McAfeePacked-GBF!5ED271E10BA3
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00578fa11 )
BitDefenderGen:Variant.Midie.79843
K7GWTrojan ( 00578fa11 )
ArcabitTrojan.Midie.D137E3
BitDefenderThetaGen:NN.ZexaF.34608.ry0@aa5uCqlG
CyrenW32/Trojan.PLLC-3292
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Injuke.gen
AlibabaTrojan:Win32/Kryptik.cedc735a
TencentWin32.Trojan.Injuke.Taza
Ad-AwareGen:Variant.Midie.79843
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.mexwf
DrWebTrojan.Siggen12.33291
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.mexwf
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Agent.vb
MicrosoftTrojan:Win32/Azorult.NC!MTB
AhnLab-V3Trojan/Win.Hynamer.R371469
ZoneAlarmHEUR:Trojan.Win32.Injuke.gen
GDataGen:Variant.Midie.79843
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Kryptik.HJWA
ALYacGen:Variant.Midie.79843
MAXmalware (ai score=100)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CCA21
RisingTrojan.Kryptik!1.D387 (CLOUD)
IkarusTrojan-Dropper.Agent
eGambitUnsafe.AI_Score_96%
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HwoCztQA

How to remove Trojan:Win32/Azorult.NC!MTB?

Trojan:Win32/Azorult.NC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment