Ransom

Should I remove “Ransom:AutoIt/RedBoot.A”?

Malware Removal

The Ransom:AutoIt/RedBoot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:AutoIt/RedBoot.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Collects and encrypts information about the computer likely to send to C2 server
  • Attempted to write directly to a physical drive

How to determine Ransom:AutoIt/RedBoot.A?


File Info:

name: 1001a8c7f33185217e6e1bdbb8dba9780d475da944684fb4bf1fc04809525887
path: /opt/CAPEv2/storage/binaries/1001a8c7f33185217e6e1bdbb8dba9780d475da944684fb4bf1fc04809525887
crc32: 5200F1DC
md5: e0340f456f76993fc047bc715dfdae6a
sha1: d47f6f7e553c4bc44a2fe88c2054de901390b2d7
sha256: 1001a8c7f33185217e6e1bdbb8dba9780d475da944684fb4bf1fc04809525887
sha512: cac10c675d81630eefca49b2ac4cc83f3eb29115ee28a560db4d6c33f70bf24980e48bb48ce20375349736e3e6b23a1ca504b9367917328853fffc5539626bbc
ssdeep: 24576:/4GHnhIzOasqUgEOr69/BRH7dCibu+XoAX0eOTva49ttrSpt81ekHPyWe:AshdasJgEOrGBRxCihH7OO49rveMG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103452394A452D017D2C67AB9C036DAB45BA4B831EEC2391BC354F651BD70383CB67B2E
sha3_384: 922c1b16487469dc8a96601b18dbd41e188652c12f7d031600d13a5dd8a6272d642911c67df09203b1ac0291330c9a8e
ep_bytes: 60be00d055008dbe0040eaff57eb0b90
timestamp: 2017-09-17 04:13:14

Version Info:

FileVersion: 1.0.0.0
Comments: None
FileDescription: None
ProductVersion: 3.3.14.2
LegalCopyright: None
Translation: 0x0409 0x04b0

Ransom:AutoIt/RedBoot.A also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.KillMBR.4!c
CynetMalicious (score: 99)
CAT-QuickHealTrojanRansom.Agent
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.78503
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/KillMBR.1d62177b
K7GWTrojan ( 700000111 )
Cybereasonmalicious.56f769
SymantecRansom.Redboot
ESET-NOD32Win32/Filecoder.Autoit.H
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Autit-8177147-0
KasperskyTrojan.Win32.KillMBR.gff
BitDefenderTrojan.GenericKD.6010862
NANO-AntivirusTrojan.Win32.GenericKD.eszujj
ViRobotTrojan.Win32.S.Ransom.1246725
MicroWorld-eScanTrojan.GenericKD.6010862
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.6010862
SophosMal/Autoit-AE
ComodoMalware@#3f8wd4aintyee
DrWebTrojan.MulDrop7.41556
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_REDBOOT.A
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.e0340f456f76993f
EmsisoftTrojan.GenericKD.6010862 (B)
GDataBoot.Trojan-Ransom.Redboot.A
WebrootW32.Trojan.GenKD
AviraDR/Autoit.zbqnm
Antiy-AVLTrojan/Generic.ASMalwS.33D8CEC
KingsoftWin32.Troj.Killmbr.ac.(kcloud)
GridinsoftRansom.Win32.Ransom.oa!s2
ArcabitTrojan.Generic.D5BB7EE
MicrosoftRansom:AutoIt/RedBoot.A
TACHYONTrojan/W32.KillMBR.1723397
AhnLab-V3Trojan/Win32.Ransom.C2162290
McAfeeGeneric Trojan.ei
MAXmalware (ai score=100)
VBA32Trojan.KillMBR
MalwarebytesMalware.AI.2942611088
TrendMicro-HouseCallRansom_REDBOOT.A
TencentMalware.Win32.Gencirc.11496bd2
eGambitUnsafe.AI_Score_86%
FortinetW32/Filecoder.H!tr
BitDefenderThetaGen:NN.ZexaF.34266.s8Z@amxnGMd
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:AutoIt/RedBoot.A?

Ransom:AutoIt/RedBoot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment