Trojan

Trojan:Win32/AzorultCrypt.AC!MTB removal guide

Malware Removal

The Trojan:Win32/AzorultCrypt.AC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AzorultCrypt.AC!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/AzorultCrypt.AC!MTB?


File Info:

name: FD7A0138399CFC377192.mlw
path: /opt/CAPEv2/storage/binaries/0067b5267550c8fa5168bbcb6da0f93d8e961c79ab4e1406d4138cdc24049cfb
crc32: B42D007D
md5: fd7a0138399cfc37719263c41e8afa8b
sha1: dfe69b4bb4ef216a0fb5495e12ef4d2fff823539
sha256: 0067b5267550c8fa5168bbcb6da0f93d8e961c79ab4e1406d4138cdc24049cfb
sha512: a1bed84094dcb8cad3e4e8e322e3230f5f4aabdf94142669a4de2c0874957e777ba078d0754418ee4eb3ab9478289c247608a32ce04ac2a2d53afbedb1e0b8d8
ssdeep: 384:cQvlcYmDee3RFzJ4hSbGY15mUBSn75/Sqc/3sMHfUgYQIAJKmp8miM6R0QvWSIVG:cQKYmvD1XG07gRpc8xCVVq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15023295FA2B4D7B2E73943BD0A249AA8085BBC34D9458E03E50B3E9D0E31E0DD5D1B1B
sha3_384: 38e79f3882d95d75c8f93e6de2f1cecd4e6712017ce4293eea2a4286403e52112f7b8559ae13b823363846d689745441
ep_bytes: 68f85e4000e8eeffffff000000000000
timestamp: 2013-12-17 14:21:58

Version Info:

Translation: 0x0409 0x04b0
Comments: CircusMid
CompanyName: CircusMid
ProductName: Unmateunderalde
FileVersion: 1.00
ProductVersion: 1.00
InternalName: precomputations
OriginalFilename: precomputations.exe

Trojan:Win32/AzorultCrypt.AC!MTB also known as:

LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.dm0@QOVwsmoi
ClamAVWin.Trojan.Ponystealer-9784162-0
FireEyeGeneric.mg.fd7a0138399cfc37
SkyhighFareit-FQW!FD7A0138399C
McAfeeFareit-FQW!FD7A0138399C
Cylanceunsafe
ZillyaTrojan.Azorult.Win32.11
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Azorult.c57f678e
K7GWTrojan ( 0056f0041 )
K7AntiVirusTrojan ( 0056f0041 )
ArcabitTrojan.PonyStealer.ED291B
BitDefenderThetaGen:NN.ZevbaCO.36744.dm0@aOVwsmoi
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.ENJB
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Azorult.apcn
BitDefenderGen:Heur.PonyStealer.dm0@QOVwsmoi
NANO-AntivirusTrojan.Win32.Azorult.hwztca
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan-QQPass.QQRob.Kzfl
EmsisoftTrojan.Injector (A)
F-SecureHeuristic.HEUR/AGEN.1333970
DrWebTrojan.PWS.Siggen2.55909
VIPREGen:Heur.PonyStealer.dm0@QOVwsmoi
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1333970
Antiy-AVLTrojan[PSW]/Win32.AZORult
Kingsoftmalware.kb.a.862
MicrosoftTrojan:Win32/AzorultCrypt.AC!MTB
ZoneAlarmTrojan-PSW.Win32.Azorult.apcn
GDataGen:Heur.PonyStealer.dm0@QOVwsmoi
VaristW32/VBInject.AEJ.gen!Eldorado
AhnLab-V3Trojan/Win32.Injector.R351761
VBA32BScope.Backdoor.Agent
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingTrojan.Injector!8.C4 (TFE:5:9E1mlwZ9yQK)
YandexTrojan.Injector!BkA0u8rAybU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/GuLoader.VHJQ!tr
AVGWin32:InjectorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/AzorultCrypt.AC!MTB?

Trojan:Win32/AzorultCrypt.AC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment