Backdoor

Backdoor.AutoIt malicious file

Malware Removal

The Backdoor.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.AutoIt virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system

Related domains:

remitancegp.duckdns.org

How to determine Backdoor.AutoIt?


File Info:

crc32: 2CBC6363
md5: fd9148837263d2993be8620217f1d093
name: FD9148837263D2993BE8620217F1D093.mlw
sha1: 80c5fb9b3cdcad615ff449366105d2bad2a88496
sha256: 517bf9cf70ce6654e7dc463e24658ebf73036b84d94f3dba067804d355feda31
sha512: 3b90fb86c79b7ced50bbc44bde97f3ae67b852aaef37c537ce91a94d46d97a7af11132f80bf654595d85f0778f2bc5242011521f1ecf63bccec71bcc9705403e
ssdeep: 24576:+rl6kD68JmloORX9FpAk6SAl/+PiHTg6b9V:8l328U2cXnpt4WP8Tg6j
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: RMActivate
FileVersion: 883.639.551.178
CompanyName: tabcal
ProductName: xcopy
ProductVersion: 25.862.807.771
FileDescription: sftp
OriginalFilename: diskperf
Translation: 0x0409 0x04b0

Backdoor.AutoIt also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
FireEyeGeneric.mg.fd9148837263d299
CAT-QuickHealBackdoor.AutoIt
McAfeePacked-FTE!FD9148837263
VIPREPacker.NSAnti.Gen (v)
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.AutoIT.16
K7GWTrojan ( 700000111 )
Cybereasonmalicious.37263d
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
BitDefenderThetaAI:Packer.D2112E0817
CyrenW32/AutoIt.QA2.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
ClamAVWin.Malware.Nymeria-6963007-0
KasperskyBackdoor.Win32.AutoIt.ed
Ad-AwareGen:Trojan.Heur.AutoIT.16
SophosTroj/AutoIt-CLG
F-SecureHeuristic.HEUR/AGEN.1114570
DrWebTrojan.AutoIt.421
InvinceaML/PE-A + Troj/AutoIt-CLG
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.cc
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
IkarusTrojan-Spy.HawkEye
AviraHEUR/AGEN.1114570
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftTrojan:Win32/Wacatac.D5!ml
ArcabitTrojan.Heur.AutoIT.16
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmBackdoor.Win32.AutoIt.ed
GDataGen:Trojan.Heur.AutoIT.16
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3201746
Acronissuspicious
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.Generic
ESET-NOD32a variant of Win32/Packed.AutoIt.PK
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
eGambitUnsafe.AI_Score_93%
FortinetAutoIt/Scar.RWET!tr
MaxSecureTrojan.Malware.300983.susgen
AVGAutoIt:Injector-JF [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.AutoIt?

Backdoor.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment