Malware

Downloader.AutoIT.Agent.A removal tips

Malware Removal

The Downloader.AutoIT.Agent.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.AutoIT.Agent.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Downloader.AutoIT.Agent.A?


File Info:

name: 3B365848891310C685E2.mlw
path: /opt/CAPEv2/storage/binaries/b2f20c957ae7b47753236fe903882c0b4a342c617a50125626e108eb1848a4a2
crc32: F3B113F1
md5: 3b365848891310c685e2e26c3665eef9
sha1: 7db4e88e4b9e5c91c55b3fb08db3649ca6c1f937
sha256: b2f20c957ae7b47753236fe903882c0b4a342c617a50125626e108eb1848a4a2
sha512: 62a817becca57b55c99017c96712a0e446f2ca40c4fa195ffbc207095ee9cf9591cda864db7dfc42be07c0fab46f79a53c55595bc2bd3ef982322e60184e5ed7
ssdeep: 24576:Vtb20pkaCqT5TBWgNjVYg0VtjzKJ9TtrkI8JOR5dxnxFzQJ9TtFJiUT7dU4Ht9d+:GVg5tjVYgUc5XVdxU5O6vdx+5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181959D2127EC9754D2BE477665B056005BB6BC228666F64E3FEC24FD3F313908A1A723
sha3_384: 6f2c58fc993e892327d1eb247e174103f0043705c6009affc2fae67d79e1fea0cc61a8f8914de6f05c3b17adb2ab19e8
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2017-10-12 09:01:26

Version Info:

FileVersion: 2.8.3.5
Comments: CHIP Secured Installer
FileDescription: CHIP Secured Installer
ProductVersion: 2.8.3.5
LegalCopyright: Copyright © 2017 Chip Digital GmbH
CompanyName: CHIP Digital GmbH
InternalName: CHIP Secured Installer
ProductName: CHIP Secured Installer
OriginalFilename: CHIP Secured Installer
Translation: 0x0407 0x04b0

Downloader.AutoIT.Agent.A also known as:

Elasticmalicious (high confidence)
DrWebAdware.Covus.33
FireEyeGeneric.mg.3b365848891310c6
CAT-QuickHealDownloader.AutoIT.Agent.A
Cybereasonmalicious.e4b9e5
CyrenW32/DownloadSponsor.B.gen!Eldorado
SymantecPUA.DownloadSponsor
ESET-NOD32Win32/DownloadSponsor.C potentially unwanted
TrendMicro-HouseCallPUA.MSIL.DownloadSponsor.SMDR
ClamAVWin.Dropper.Miner-7086571-0
Kasperskynot-a-virus:HEUR:Downloader.MSIL.DownloadSponsor.gen
NANO-AntivirusRiskware.Script.Downware.evryrn
AvastWin32:PUP-gen [PUP]
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.MSIL.DownloadSponsor.SMDR
McAfee-GW-EditionBehavesLike.Win32.PUP.th
EmsisoftApplication.AdLoad (A)
Antiy-AVLTrojan/Generic.ASCommon.1B7
MicrosoftPUA:Win32/Caypnamer.A!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DownloadSponsor.R213134
McAfeeArtemis!3B3658488913
TACHYONTrojan/W32.Startun.2008576
VBA32Trojan.Download
MalwarebytesPUP.Optional.ChipDe
APEXMalicious
RisingPUF.DownloadSponsor!1.BE33 (CLASSIC)
YandexPUA.Downloader!5vCFxtRs+2k
IkarusPUA.DownloadSponsor
MaxSecureDownloader.Agent.efha
FortinetAutoIt/Dloader.SM!tr
AVGWin32:PUP-gen [PUP]
PandaTrj/Genetic.gen

How to remove Downloader.AutoIT.Agent.A?

Downloader.AutoIT.Agent.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment