Trojan

Trojan:Win32/Ousetuu.A removal guide

Malware Removal

The Trojan:Win32/Ousetuu.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ousetuu.A virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Ousetuu.A?


File Info:

name: 2E1C7B4D9254E7EC9A3E.mlw
path: /opt/CAPEv2/storage/binaries/10a5a92b7e6864849a7ff8040f2a1ca2446595d121fc1cc05aaa84b9692f5fa1
crc32: E2BF1EB8
md5: 2e1c7b4d9254e7ec9a3e318d43d637d9
sha1: 0a5b8e93ee9a9f3325edc9143837a46b72cb2128
sha256: 10a5a92b7e6864849a7ff8040f2a1ca2446595d121fc1cc05aaa84b9692f5fa1
sha512: 6c83757b94a31092e113b540917f130c21421156c56de7ce0541ba25ac95249abc3358fb22a796e9ff680b55d66708ce96ecf0a738c998ca4c69b22cc34f5cb2
ssdeep: 12288:Utb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgakTaKql6A:Utb20pkaCqT5TBWgNQ7aEBql6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B25BF1373DE8360C3B25273BA65B701BEBF782506A5F56B2FD4093DE920122525EA73
sha3_384: 8f3764dc64557db2f494a01024b853bae222692d5fe5e79c9c70a204c77c1aa840c5889d39f6ac0447fd483c6dfb0107
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2014-10-23 16:53:49

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/Ousetuu.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.4!c
MicroWorld-eScanWin32.Worm.Autoit.JU
FireEyeWin32.Worm.Autoit.JU
CAT-QuickHealTrojanPWS.AutoIt.Zbot.S
McAfeeArtemis!2E1C7B4D9254
MalwarebytesGeneric.Malware/Suspicious
SangforWorm.Win32.Autoit.V44f
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Ousetuu.3fe7c5aa
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.EGZN-5521
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.Autoit.BAK
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Inject.temb
BitDefenderWin32.Worm.Autoit.JU
NANO-AntivirusTrojan.Win32.Inject.djefcp
AvastWin32:Agent-AULK [Trj]
TencentWin32.Trojan.Inject.Gjgl
SophosMal/Generic-S
F-SecureTrojan.TR/Drop.AutoIt.BAK
DrWebTrojan.Siggen6.25803
VIPREWin32.Worm.Autoit.JU
TrendMicroPAK_Otorun8
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dh
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Worm.Autoit.JU (B)
IkarusTrojan.Win32.Inject
GDataWin32.Worm.Autoit.JU
WebrootW32.Trojan.Gen
AviraTR/Drop.AutoIt.BAK
Antiy-AVLGrayWare/Autoit.BinToStr.a
XcitiumMalware@#1ebywgbgngo7z
ArcabitWin32.Worm.Autoit.JU
ZoneAlarmTrojan.Win32.Inject.temb
MicrosoftTrojan:Win32/Ousetuu.A
GoogleDetected
BitDefenderThetaAI:Packer.330BDA6516
ALYacWin32.Worm.Autoit.JU
MAXmalware (ai score=100)
VBA32Trojan.Autoit.Paket
Cylanceunsafe
PandaTrj/Chgt.J
ZonerTrojan.Win32.Autoit.27723
TrendMicro-HouseCallPAK_Otorun8
SentinelOneStatic AI – Suspicious PE
FortinetW32/Inject.TEMB!tr
AVGWin32:Agent-AULK [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Ousetuu.A?

Trojan:Win32/Ousetuu.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment