Trojan

How to remove “Trojan:Win32/Azorult.NY!MTB”?

Malware Removal

The Trojan:Win32/Azorult.NY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.NY!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Hongkong)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
api.faceit.com
a.tomx.xyz

How to determine Trojan:Win32/Azorult.NY!MTB?


File Info:

crc32: 42835F78
md5: 698a9902103578f152a60f3e7daefa63
name: 698A9902103578F152A60F3E7DAEFA63.mlw
sha1: 0664fb976c854b0f23323794286e28936976998a
sha256: 5e15f8b94afa9b7b74c043b1742a351fa5216b32e0a7eb6733f7a209fbce4879
sha512: ea2cd691436f0ab86333d5c46b0117d1fe45beff09f29c80079cee6baa3de6cb42e40bfb52dc79724da3512dc2a02fee4309720eed38f1827f741722a65479a5
ssdeep: 12288:/SOPW5vPtULQICKr4DwnKSSKbTy1DfQIIr8MCXZSCKdw:/3IPtUJpkDW7bTEDBIOECKS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVers: 7.0.21.21
InternalNames: galimatimat
FileVers: 7.0.4.54
LegalCopyrighd: Jdfgl sfd
Translations: 0x0169 0x20bb

Trojan:Win32/Azorult.NY!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057c2eb1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.65027
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.75064
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057c2eb1 )
Cybereasonmalicious.76c854
CyrenW32/Kryptik.EAT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKUF
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.Generic-9860053-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKDZ.75064
NANO-AntivirusTrojan.Win32.Chapak.ivfzii
MicroWorld-eScanTrojan.GenericKDZ.75064
Ad-AwareTrojan.GenericKDZ.75064
SophosML/PE-A + Troj/Agent-BHBV
BitDefenderThetaGen:NN.ZexaF.34170.OuW@a0Of7doj
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.jc
FireEyeGeneric.mg.698a9902103578f1
EmsisoftTrojan.GenericKDZ.75064 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.VidarStealer.tixle
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Azorult.NY!MTB
GDataTrojan.GenericKDZ.75064
AhnLab-V3CoinMiner/Win.Glupteba.R419932
Acronissuspicious
McAfeePacked-GBF!698A99021035
MAXmalware (ai score=84)
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.MalPack
RisingTrojan.Kryptik!1.D599 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HKUF!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Trojan:Win32/Azorult.NY!MTB?

Trojan:Win32/Azorult.NY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment