Malware

AutoIt:ShellCode-B [Trj] malicious file

Malware Removal

The AutoIt:ShellCode-B [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoIt:ShellCode-B [Trj] virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine AutoIt:ShellCode-B [Trj]?


File Info:

crc32: 32335971
md5: 74daaafc2cf0d60ff92a19f196e87c9b
name: 74DAAAFC2CF0D60FF92A19F196E87C9B.mlw
sha1: 7b1181f42b447cbb1e1a186bc84e9ecec3702859
sha256: d583efaa0e38529af37977835743b66742521bc45752cfa5bc435847951dc88b
sha512: eb578a16da8a2f16f8aba6276490e1e64a760668049c4c84df9a5afc2e4a7802b6863742a98de0a923604beec904f40e291e1ea8ce00d8da101480438868fc25
ssdeep: 24576:eRmJkcoQricOIQxiZY1iaBC9csKC2tflo:LJZoQrbTFZY1iaRbu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

AutoIt:ShellCode-B [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.64539
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.1949111
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000111 )
Cybereasonmalicious.c2cf0d
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:ShellCode-B [Trj]
ClamAVWin.Malware.Autoit-9845824-0
KasperskyTrojan.Win32.Autoit.dxy
BitDefenderTrojan.GenericKD.1949111
NANO-AntivirusTrojan.Script.Agent.debxaj
MicroWorld-eScanTrojan.GenericKD.1949111
Ad-AwareTrojan.GenericKD.1949111
SophosML/PE-A
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R005C0DF621
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.fh
FireEyeGeneric.mg.74daaafc2cf0d60f
EmsisoftTrojan.GenericKD.1949111 (B)
AviraHEUR/AGEN.1110296
MicrosoftVirTool:Win32/Obfuscator.AKT
GDataTrojan.GenericKD.1949111
McAfeeTrojan-AitInject.cm
MAXmalware (ai score=82)
VBA32Trojan.Autoit
MalwarebytesTrojan.Agent.AI
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DF621
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Autoit.AZA
FortinetW32/Autoit.AKN!tr
AVGAutoIt:ShellCode-B [Trj]

How to remove AutoIt:ShellCode-B [Trj]?

AutoIt:ShellCode-B [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment