Malware

AutoIt:Dropper-F [Drp] removal tips

Malware Removal

The AutoIt:Dropper-F [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoIt:Dropper-F [Drp] virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
ebukaalilonu.zapto.org

How to determine AutoIt:Dropper-F [Drp]?


File Info:

crc32: 904ADD12
md5: 2c9e48d7852e1a8471ad7e8075a3a237
name: 2C9E48D7852E1A8471AD7E8075A3A237.mlw
sha1: cee12ba611fb9ac24483668950cd01b78763257c
sha256: daf7c3756f7a7e2f94f3c0981d34e14dec4f4fa62393d375c71d8de034041abf
sha512: 2c3195419fda5575a323828134950a8582c100f8438f8f6021a8ccf342358879cf49aa5004bbdfe30c12db1c99c56188f8f5f29e6793012e3e957818e0f8bc64
ssdeep: 24576:PRmJkcoQricOIQxiZY1WNFw8Jl5VV+CaM6tQkFuYaTCtvFn/F9qiQ:EJZoQrbTFZY1WNFwSP+PM61FKWnm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

AutoIt:Dropper-F [Drp] also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Autoit.mcXb
Elasticmalicious (high confidence)
DrWebTrojan.Bankfraud.3628
ClamAVWin.Malware.Autoit-6912463-0
ALYacTrojan.GenericKD.41415387
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/Banker.b5a3490f
K7GWSpyware ( 004fbe541 )
K7AntiVirusSpyware ( 004fbe541 )
CyrenW32/Autoit.AQQU-2891
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Dropper-F [Drp]
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Autoit.abceqi
BitDefenderTrojan.GenericKD.41415387
NANO-AntivirusTrojan.Win32.Bankfraud.efjtmx
MicroWorld-eScanTrojan.GenericKD.41415387
TencentWin32.Trojan-dropper.Autoit.Htwo
Ad-AwareTrojan.GenericKD.41415387
SophosMal/Generic-S
BitDefenderThetaAI:Packer.0DA08E8C16
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Lokmwiz.R002C0CFE21
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
FireEyeGeneric.mg.2c9e48d7852e1a84
EmsisoftTrojan.GenericKD.41415387 (B)
JiangminTrojanDropper.Autoit.dhs
AviraHEUR/AGEN.1116018
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASCommon.168
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftRansom:AutoIt/Lokmwiz.A
ArcabitTrojan.Generic.D277F2DB
ZoneAlarmTrojan-Dropper.Win32.Autoit.abceqi
GDataTrojan.GenericKD.41415387
AhnLab-V3Dropper/Win32.RL_Autoit.R366525
Acronissuspicious
McAfeeArtemis!2C9E48D7852E
MAXmalware (ai score=87)
VBA32Trojan.Autoit.F
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Lokmwiz.R002C0CFE21
RisingTrojan.Obfus/Autoit!1.BEDE (CLASSIC)
YandexTrojan.GenAsa!IZxoZO1iAfE
IkarusTroajn-Ransom.Crypt888
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.BQ!tr
AVGAutoIt:Dropper-F [Drp]
Paloaltogeneric.ml

How to remove AutoIt:Dropper-F [Drp]?

AutoIt:Dropper-F [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment