Malware

AIT.Heur.VictoryGate.1.F424CA84.Gen malicious file

Malware Removal

The AIT.Heur.VictoryGate.1.F424CA84.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT.Heur.VictoryGate.1.F424CA84.Gen virus can do?

  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AIT.Heur.VictoryGate.1.F424CA84.Gen?


File Info:

name: 5E80E8F1538707C28460.mlw
path: /opt/CAPEv2/storage/binaries/310a4f9adcef76185ce44ab45a240209b89a87039a085f83a208cbd0cf5e83b2
crc32: C8A4209D
md5: 5e80e8f1538707c28460b4c3060620c2
sha1: d748dcca83d719025d47ded4fbf6070135bf476b
sha256: 310a4f9adcef76185ce44ab45a240209b89a87039a085f83a208cbd0cf5e83b2
sha512: b5f3e6de9612527186ba0a2d28b08cdf058c97b98c36abdcf14723fdc4af1778a806327ffadcc20582e45485766fdda1f2186d6e3620ae83933c305fd31ea294
ssdeep: 12288:+CdOy3vVrKxR5CXbNjAOxK/j2n+4YG/6c1mFFja3mXgcjfRlgsUBga4z7Q:+Cdxte/80jYLT3U1jfsWa4z7Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8058C2273DDC360CB669173BF69B7016EBF78650630F85B2F880D79A950171262DBA3
sha3_384: 0894af97ce1c640b8c1e2008c16c3bbee571f6a2870baf580baf3f4a52c2e073c9ea358ab49211452a86ed22abcc3180
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2023-07-27 16:47:17

Version Info:

CompanyName: eyVrSNdCV
FileVersion: 0.0.0.0
Translation: 0x0809 0x04b0

AIT.Heur.VictoryGate.1.F424CA84.Gen also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanAIT.Heur.VictoryGate.1.F424CA84.Gen
ALYacAIT.Heur.VictoryGate.1.F424CA84.Gen
MalwarebytesTrojan.MalPack
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0054bc841 )
AlibabaTrojan:Win32/AutoitShellInj.ac535600
K7GWTrojan ( 0054bc841 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MulDrop8.HPR
CyrenW32/AutoIt.SQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Autoit.OGC
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Script.Generic
BitDefenderAIT.Heur.VictoryGate.1.F424CA84.Gen
AvastAutoIt:Runner-BG [Trj]
TencentWin32.Trojan.Autoit.Zchl
EmsisoftAIT.Heur.VictoryGate.1.F424CA84.Gen (B)
F-SecureWorm.WORM/FakeExt.Gen8
VIPREAIT.Heur.VictoryGate.1.F424CA84.Gen
TrendMicroTROJ_GEN.R002C0DHG23
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
FireEyeAIT.Heur.VictoryGate.1.F424CA84.Gen
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
GDataAIT.Heur.VictoryGate.1.F424CA84.Gen (2x)
WebrootW32.Trojan.Gen
AviraWORM/FakeExt.Gen8
Antiy-AVLGrayWare/Autoit.WorkingDir.a
ArcabitAIT.Heur.VictoryGate.1.F424CA84.Gen [many]
ViRobotTrojan.Win.Z.Autoit.838656.DM
ZoneAlarmHEUR:Trojan.Script.Generic
MicrosoftTrojan:Win32/AutoitShellInj.EA!MTB
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R304213
McAfeeTrojan-aitinject.af
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DHG23
RisingTrojan.Agent/Autoit!1.BB61 (CLASSIC)
IkarusTrojan.Win32.Autoit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autoit.OGC!tr
AVGAutoIt:Runner-BG [Trj]
DeepInstinctMALICIOUS

How to remove AIT.Heur.VictoryGate.1.F424CA84.Gen?

AIT.Heur.VictoryGate.1.F424CA84.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment