Backdoor

Backdoor.Win32.AutoIt.ed removal instruction

Malware Removal

The Backdoor.Win32.AutoIt.ed is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.AutoIt.ed virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to remove evidence of file being downloaded from the Internet
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
remitancegp.duckdns.org

How to determine Backdoor.Win32.AutoIt.ed?


File Info:

crc32: 93580C55
md5: 93131f22f916ef09d8557f9c9e338814
name: 93131F22F916EF09D8557F9C9E338814.mlw
sha1: 920e568c06aa4d6370bb1d81c0a25936117017a3
sha256: 7281889000027d55fe9ea221aac1fa00f269c66235a1583fd950b364641a6d67
sha512: a75c222a5d90c32a9070401460a6377647bd01a5c479f23a0bebf43726d9de5499aff9b9b8de799a40086028b94508ec43907b867cac5e1aa6d33312442b8583
ssdeep: 24576:+rl6kD68JmloOtX9FpAk6SAl/+PiHTg6b9S:8l328U2UXnpt4WP8Tg68
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: RMActivate
FileVersion: 883.639.551.178
CompanyName: tabcal
ProductName: xcopy
ProductVersion: 25.862.807.771
FileDescription: sftp
OriginalFilename: diskperf
Translation: 0x0409 0x04b0

Backdoor.Win32.AutoIt.ed also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
CAT-QuickHealBackdoor.AutoIt
McAfeePacked-FTE!93131F22F916
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.AutoIT.16
K7GWTrojan ( 700000111 )
Cybereasonmalicious.2f916e
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
CyrenW32/AutoIt.QA2.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
ClamAVWin.Malware.Nymeria-6963007-0
KasperskyBackdoor.Win32.AutoIt.ed
TencentMalware.Win32.Gencirc.10ce12d3
Ad-AwareGen:Trojan.Heur.AutoIT.16
SophosTroj/AutoIt-CLG
F-SecureHeuristic.HEUR/AGEN.1114570
DrWebTrojan.AutoIt.421
InvinceaML/PE-A + Troj/AutoIt-CLG
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.cc
FireEyeGeneric.mg.93131f22f916ef09
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
IkarusTrojan-Spy.HawkEye
AviraHEUR/AGEN.1114570
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftTrojan:Win32/Wacatac.D7!ml
ArcabitTrojan.Heur.AutoIT.16
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmBackdoor.Win32.AutoIt.ed
GDataGen:Trojan.Heur.AutoIT.16
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3201746
Acronissuspicious
BitDefenderThetaAI:Packer.D2112E0817
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.Generic
ESET-NOD32a variant of Win32/Packed.AutoIt.PK
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
eGambitUnsafe.AI_Score_94%
FortinetAutoIt/Scar.RWET!tr
AVGAutoIt:Injector-JF [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.AutoIt.ed?

Backdoor.Win32.AutoIt.ed removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment