Malware

AutoIt:MalOb-BZ [Trj] removal tips

Malware Removal

The AutoIt:MalOb-BZ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoIt:MalOb-BZ [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Deletes executed files from disk
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AutoIt:MalOb-BZ [Trj]?


File Info:

name: 1BD605743807FFCA8F0E.mlw
path: /opt/CAPEv2/storage/binaries/7510f5d7a421e7b0480765921cf5639ca666f371fbff986aabce7fefa5d0717d
crc32: 63D28FA7
md5: 1bd605743807ffca8f0ee871741af3eb
sha1: 9d83fb2a8a607fd5b88cab250af0657f2613aaa7
sha256: 7510f5d7a421e7b0480765921cf5639ca666f371fbff986aabce7fefa5d0717d
sha512: 7ab44e8dfe42e2086d193300b443da6e6e72642ab442163b35216a9ebb9f4ac3823422d6ea58e6b9638e088050d59eb09f4a68a2a24868b482ab7503b6af4f57
ssdeep: 98304:48sjkmhRWieWT0ywsagZ9VeXD3fwGCbU:6jhhRPeWvnzwrfj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5F5122277DEC360CB6A91B7BF69B7116FBF7C650630B85B1E882D78B960061112C763
sha3_384: 769848e68db397b0c23b4c2b0f7adf66983bf9c68a2535859755d7740c3af936e2cfc8f1c79a0061530f4a81a5fdd602
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2023-06-02 09:02:31

Version Info:

Translation: 0x0809 0x04b0

AutoIt:MalOb-BZ [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Strictor.102909
FireEyeGeneric.mg.1bd605743807ffca
CAT-QuickHealTrojan.HackTool
ALYacGen:Variant.Strictor.102909
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREGen:Variant.Strictor.102909
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Strictor.102909
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Strictor.D191FD
BitDefenderThetaGen:NN.ZexaF.36318.1pNfaCUzYHli
CyrenW32/A-aa93a15d!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Malware.Aa93a15d-6745814-0
KasperskyTrojan.Win32.Tremp.jii
NANO-AntivirusTrojan.Win32.Tremp.jwnkor
EmsisoftGen:Variant.Strictor.102909 (B)
F-SecureHeuristic.HEUR/AGEN.1319390
DrWebTrojan.MulDrop22.13440
TrendMicroCRCK_KEYGEN
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.wc
SophosGeneric Reputation PUA (PUA)
IkarusHackTool.Keygen.WindowsLoader
GoogleDetected
AviraHEUR/AGEN.1319390
Antiy-AVLWorm/Win32.AutoRun
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmHackTool.Win32.KMSAuto.bu
GDataGen:Variant.Strictor.102909
CynetMalicious (score: 100)
AhnLab-V3HackTool/Win.Agent.R431893
McAfeeArtemis!1BD605743807
MAXmalware (ai score=87)
Cylanceunsafe
TrendMicro-HouseCallCRCK_KEYGEN
SentinelOneStatic AI – Malicious PE
FortinetRiskware/KMSAuto
AVGAutoIt:MalOb-BZ [Trj]
Cybereasonmalicious.43807f
AvastAutoIt:MalOb-BZ [Trj]

How to remove AutoIt:MalOb-BZ [Trj]?

AutoIt:MalOb-BZ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment