Trojan

AIT:Trojan.Autoit.RNU (file analysis)

Malware Removal

The AIT:Trojan.Autoit.RNU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Autoit.RNU virus can do?

  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Anomalous binary characteristics

How to determine AIT:Trojan.Autoit.RNU?


File Info:

crc32: 3E2C7097
md5: eba3ba3e866d58ab5a79cd6300666c78
name: EBA3BA3E866D58AB5A79CD6300666C78.mlw
sha1: 14e98d6cfe1a4cc96235ddb1f8259c445b75439e
sha256: 6cf626cf2a16bd957ba979df981dc1bf20c7689b374f9ed2f99687b983e6f8f8
sha512: e8f2987a4106bf3be14526ff2ce999bdf38fa58370ad36db6baf64add18fa4886b95d481ceea302e597ecf773c16779981377f79a52e13051c4bbdac81c40a67
ssdeep: 24576:uRmJkcoQricOIQxiZY1iaCbdBOYI9z7ogKQt91Eamg/4GK:7JZoQrbTFZY1iaCk9z8VY9b4GK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

AIT:Trojan.Autoit.RNU also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 700000111 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacAIT:Trojan.Autoit.RNU
CylanceUnsafe
ZillyaTrojan.Fakeoff.Win32.297
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Fakeoff.dcc9287f
K7GWTrojan ( 700000111 )
Cybereasonmalicious.e866d5
CyrenW32/AutoIt.AQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.GSZNJLB
APEXMalicious
AvastWin32:Dropper-gen [Drp]
ClamAVWin.Malware.Autoit-9880096-0
KasperskyTrojan.Win32.Fakeoff.dwe
BitDefenderAIT:Trojan.Autoit.RNU
NANO-AntivirusTrojan.Win32.Fakeoff.foafcx
MicroWorld-eScanAIT:Trojan.Autoit.RNU
TencentWin32.Trojan.Fakeoff.Anfn
Ad-AwareAIT:Trojan.Autoit.RNU
SophosMal/Generic-S
ComodoMalware@#3limjj73aoabw
BitDefenderThetaAI:Packer.C68070AE15
VIPRETrojan.Win32.Generic!BT
TrendMicroWorm.AutoIt.MOZGOO.A
McAfee-GW-EditionBehavesLike.Win32.Yahlover.tc
FireEyeGeneric.mg.eba3ba3e866d58ab
EmsisoftAIT:Trojan.Autoit.RNU (B)
JiangminTrojan.Generic.bimkf
AviraHEUR/AGEN.1110325
eGambitUnsafe.AI_Score_79%
MicrosoftTrojan:Win32/Occamy.C6C
ArcabitAIT:Trojan.Autoit.RNU
GDataAIT:Trojan.Autoit.RNU (2x)
McAfeeArtemis!EBA3BA3E866D
MAXmalware (ai score=100)
VBA32BScope.Trojan.MulDrop
MalwarebytesTrojan.Dropper.AutoIt
PandaTrj/CI.A
TrendMicro-HouseCallWorm.AutoIt.MOZGOO.A
RisingTrojan.Obfus/Autoit!1.C9CD (CLASSIC)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Autoit.AZA
FortinetW32/Fakeoff.DWE!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove AIT:Trojan.Autoit.RNU?

AIT:Trojan.Autoit.RNU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment