Categories: Malware

AutoIt:KeyLogger-R [Trj] removal instruction

The AutoIt:KeyLogger-R [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoIt:KeyLogger-R [Trj] virus can do?

  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

bkefr.ddns.net
redirector.gvt1.com
r4—sn-4g5e6nzz.gvt1.com

How to determine AutoIt:KeyLogger-R [Trj]?


File Info:

crc32: 8244CD26md5: 3e805d0ee3a1e553016984ae12ecb4e9name: lagg.exesha1: d406979e1b84faabeae2ddf3b71368fb61b6a7cbsha256: a0550d5a1ff97c0759ee54fc832e3114f70f0ec4806fa6885f28b2ed677cb677sha512: 431555c61a9d21121eec50073270c21e44942857ef46e3ce3e2717cee617dcd3d643d973152ef5a73752964207fe647e4b6f719f27d6f9833d83815a8edd7c97ssdeep: 12288:qXe9PPlowWX0t6mOQwg1Qd15CcYk0We1Ho58A2ddjdbYetYtJhhKwYu:/hloDX0XOf4+eV5EAYtJhhKwztype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

AutoIt:KeyLogger-R [Trj] also known as:

MicroWorld-eScan AIT:Trojan.Nymeria.2906
McAfee AutoIt/Injector.ar
BitDefender AIT:Trojan.Nymeria.2906
CrowdStrike win/malicious_confidence_70% (D)
APEX Malicious
Avast AutoIt:KeyLogger-R [Trj]
GData AIT:Trojan.Nymeria.2906 (3x)
Kaspersky HEUR:Trojan.Script.Generic
Ad-Aware AIT:Trojan.Nymeria.2906
F-Secure Heuristic.HEUR/AGEN.1114575
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.TrojanAitInject.bc
FireEye Generic.mg.3e805d0ee3a1e553
Emsisoft AIT:Trojan.Nymeria.2906 (B)
Avira HEUR/AGEN.1114575
Endgame malicious (moderate confidence)
Arcabit AIT:Trojan.Nymeria.DB5A
ZoneAlarm HEUR:Trojan.Script.Generic
Microsoft Trojan:Win32/Wacatac.C!ml
AhnLab-V3 Malware/Win32.RL_Generic.R264020
BitDefenderTheta AI:Packer.7492DFF116
ALYac AIT:Trojan.Nymeria.2906
ESET-NOD32 a variant of Win32/Autoit.DB
Rising Trojan.Agent/Autoit!1.BC29 (CLASSIC)
MAX malware (ai score=82)
eGambit Unsafe.AI_Score_100%
Fortinet AutoIt/Agent.DB!tr
AVG AutoIt:KeyLogger-R [Trj]
Cybereason malicious.ee3a1e
MaxSecure Trojan.Malware.300983.susgen

How to remove AutoIt:KeyLogger-R [Trj]?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Malware.AI.3739112771”?

The Malware.AI.3739112771 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Generic.MSIL.Bladabindi.574A3861 (file analysis)

The Generic.MSIL.Bladabindi.574A3861 is considered dangerous by lots of security experts. When this infection is active,…

6 mins ago

Ransom.Cryfile.16952 information

The Ransom.Cryfile.16952 is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

What is “Trojan.Generic.6104163”?

The Trojan.Generic.6104163 is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

Win32/Toolbar.MyWebSearch.AO potentially unwanted (file analysis)

The Win32/Toolbar.MyWebSearch.AO potentially unwanted is considered dangerous by lots of security experts. When this infection…

26 mins ago

Malware.AI.1963292161 (file analysis)

The Malware.AI.1963292161 is considered dangerous by lots of security experts. When this infection is active,…

32 mins ago