Worm

Worm:Win32/Ainslot!pz removal guide

Malware Removal

The Worm:Win32/Ainslot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ainslot!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Unconventionial language used in binary resources: Arabic
  • Authenticode signature is invalid
  • CAPE detected the BlackshadesRAT malware family
  • Operates on local firewall’s policies and settings
  • A script or command line contains a long continuous string indicative of obfuscation
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Ainslot!pz?


File Info:

name: 5EBD8FD166E42B55E531.mlw
path: /opt/CAPEv2/storage/binaries/5cccf029efba0c0478c0e2aaa833ada8c3935281f0f0d2d20278c4bd32123cbb
crc32: B39D5421
md5: 5ebd8fd166e42b55e5318fe948ff95ce
sha1: 87942e446821fcbeb2af7c57c744de0deac6e3ac
sha256: 5cccf029efba0c0478c0e2aaa833ada8c3935281f0f0d2d20278c4bd32123cbb
sha512: d34d36373c37ed3dafe706e2f984639dea3a45fdb10b8daa95eec3aacd7f9fb456919fef7661c98009cf2883acd8bc59c04f6dfbe849b76d87875217efaff1b5
ssdeep: 6144:eCs1ergxnNvP3IZDwZdfZvkASZRHe3/bRnwDHYM6jI7v1Qz9A3LB:eCsErW33UWjMG/9nwDHYM6jI79QzO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2852F046E268C79D49F4B366EAA7AF181635B3483E742E341676F0634BA9F04D8CF17
sha3_384: 65da95724fe4a02d34f0bfffe4a6962faf06318531a148e9637d12f9ff50accf2a0e3f7334c2fb29ed47de82fed65c68
ep_bytes: 681c1d4000e8eeffffff000048000000
timestamp: 2012-03-24 01:55:39

Version Info:

0: [No Data]

Worm:Win32/Ainslot!pz also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Shakblades.lyuQ
ElasticWindows.Trojan.BlackShades
DrWebBackDoor.Blackshades.3
MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.826573AC
SkyhighBehavesLike.Win32.Generic.tt
McAfeeW32/Generic.worm!p2p.c
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Birele.Win32.6641
SangforTrojan.Win32.Save.a
AlibabaWorm:Win32/Ainslot.25b8e0aa
Cybereasonmalicious.46821f
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.DC9CCDAC
BitDefenderThetaGen:NN.ZevbaF.36680.OnW@aW3gQjcG
VirITWorm.Win32.Generic.BKVN
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Ainslot.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Keylogger.Windef-7136116-0
KasperskyTrojan-FakeAV.Win32.Windef.ncg
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.826573AC
NANO-AntivirusTrojan.Win32.Birele.cmxqat
AvastWin32:AutoIt-BYV [Trj]
RisingWorm.Win32.Anisolt.a (CLASSIC)
EmsisoftDeepScan:Generic.MSIL.PasswordStealerA.826573AC (B)
F-SecureHeuristic.HEUR/AGEN.1332846
BaiduWin32.Worm.Ainslot.a
VIPREDeepScan:Generic.MSIL.PasswordStealerA.826573AC
TrendMicroWORM_SWISYN.SM
SophosMal/VB-GI
IkarusTrojan.Crypt
JiangminTrojan/Birele.arn
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1332846
Antiy-AVLTrojan[Ransom]/Win32.Birele.ffm
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Agent.ANQ@4ps5vo
MicrosoftWorm:Win32/Ainslot!pz
ViRobotTrojan.Win32.A.Birele.1712128
ZoneAlarmTrojan-FakeAV.Win32.Windef.ncg
GDataWin32.Worm.VB.ARK
GoogleDetected
AhnLab-V3Trojan/Win32.Ransom.R58138
VBA32Malware-Cryptor.VB.gen.1
ALYacDeepScan:Generic.MSIL.PasswordStealerA.826573AC
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_SWISYN.SM
TencentWin32.Trojan-FakeAV.Windef.Hajl
YandexTrojan.GenAsa!0lRswId3SQI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3753079.susgen
FortinetW32/Cospet.HA!tr
AVGWin32:AutoIt-BYV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Ainslot!pz?

Worm:Win32/Ainslot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment