Backdoor

Backdoor:Win32/Autocrat.E removal instruction

Malware Removal

The Backdoor:Win32/Autocrat.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Autocrat.E virus can do?

  • Executable code extraction
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

Related domains:

asp.7i24.com

How to determine Backdoor:Win32/Autocrat.E?


File Info:

crc32: FC8EF933
md5: b1d603033ce830ea630848f4c35b003d
name: B1D603033CE830EA630848F4C35B003D.mlw
sha1: 5c1a2df11e07c71622e8cadc37d26429463727f0
sha256: a685a7034b69affff698d433d0efbdb48b76c3d009653c6a0c4a9c4682ce15c3
sha512: 3ebf7e4947b33c1dfdb6609811bfe61b548e7900f449f36113ea6fee0f6cb1f0cd37131d56db31d696e206d0b2506b7fab176caed2466e1886d70e133c201a30
ssdeep: 3072:aOPD2tZCM4qRpwZudX1JBkITOygPDHfaqPjr0ghzq6D/oUmhw3QiU89EybTT:d72thTwIX1JBkITOygbdPhcGAi5T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: Copyright (C) Microsoft Corp. 1985-2002
InternalName: wupdmgr32
FileVersion: 5.03.0220
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.03.0220
FileDescription: Windows Update Manager
OriginalFilename: wupdmgr32.exe

Backdoor:Win32/Autocrat.E also known as:

BkavW32.AIDetect.malware1
K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
DrWebBackDoor.Generic.497
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5254356
ALYacGen:Trojan.Malware.mm0@aGHcIScb
CylanceUnsafe
ZillyaBackdoor.Autocrat.Win32.20
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Autocrat.d486fea8
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.33ce83
CyrenW32/Trojan.OKYP-6993
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Autocrat.NAA
APEXMalicious
AvastWin32:Hucsyn-E [Trj]
ClamAVWin.Trojan.Winshell-4
KasperskyBackdoor.Win32.Autocrat.e
BitDefenderGen:Trojan.Malware.mm0@aGHcIScb
NANO-AntivirusTrojan.Win32.Autocrat.slol
MicroWorld-eScanGen:Trojan.Malware.mm0@aGHcIScb
TencentWin32.Backdoor.Autocrat.cpja
Ad-AwareGen:Trojan.Malware.mm0@aGHcIScb
SophosGeneric ML PUA (PUA)
ComodoBackdoor.Win32.Autocrat.NAA@9oh7
F-SecureBackdoor.BDS/WinShell.50.A
BitDefenderThetaAI:Packer.EB171DFA21
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_AUTOCRAT.O
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.b1d603033ce830ea
EmsisoftGen:Trojan.Malware.mm0@aGHcIScb (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Backdoor.Gen
AviraBDS/WinShell.50.A
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.C41CD
KingsoftWin32.Heur.KVM006.a.(kcloud)
MicrosoftBackdoor:Win32/Autocrat.E
ArcabitTrojan.Malware.ECEC59
ZoneAlarmBackdoor.Win32.Autocrat.e
GDataGen:Trojan.Malware.mm0@aGHcIScb
AhnLab-V3Backdoor/Win32.Autocrat.R147450
McAfeeDDoS-HeiBei
MAXmalware (ai score=100)
VBA32Trojan.VBO.011151
MalwarebytesMalware.AI.824524613
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_AUTOCRAT.O
RisingTrojan.AutoCrat.a (CLASSIC)
YandexBackdoor.Autocrat.Q
IkarusBackdoor.Win32.Death
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autocrat.E!tr.bdr
AVGWin32:Hucsyn-E [Trj]

How to remove Backdoor:Win32/Autocrat.E?

Backdoor:Win32/Autocrat.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment