Spy

Spyware.RedLineStealer.AutoIt information

Malware Removal

The Spyware.RedLineStealer.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.RedLineStealer.AutoIt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity contains more than one unique useragent.
  • The following process appear to have been packed with Themida: 1763934830.exe
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

ezstat.ru
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org
pilinno.info
ip-api.com
adsymbol.com

How to determine Spyware.RedLineStealer.AutoIt?


File Info:

crc32: 868738AB
md5: a784a20ef22ecb135c44b346e86b76d5
name: promotion.exe
sha1: d52a02b17cfc2869a9b591fb3d486ef25964647d
sha256: a529c25ccf4e344243a8e58a529fd94ef7017a8b9fc97b83b157f942ee11cb57
sha512: edf4d6726ce125e0007b3624a0cff1191731d513cb81ca0b092c1b4078922cc88730260483a5692baa4255778e88ae79d3208ca6dddca885a22e781d50f95c30
ssdeep: 24576:VAHnh+eWsN3skA4RV1Hom2KXMmHae+mxN5:Eh+ZkldoPK8YaeN9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Spyware.RedLineStealer.AutoIt also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.DownLoader34.9363
MicroWorld-eScanAIT.Heur.Cottonmouth.8.Gen
FireEyeGeneric.mg.a784a20ef22ecb13
McAfeeArtemis!A784A20EF22E
SangforMalware
K7AntiVirusTrojan-Downloader ( 005234df1 )
AlibabaTrojanDownloader:Win32/Autoit.ee4bdaf0
K7GWTrojan-Downloader ( 005234df1 )
Cybereasonmalicious.17cfc2
F-ProtW32/AutoIt.IM.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.OIY
TrendMicro-HouseCallTROJ_GEN.R002H09GS20
GDataAIT.Heur.Cottonmouth.8.Gen (2x)
KasperskyTrojan-Spy.Win32.Stealer.tej
BitDefenderAIT.Heur.Cottonmouth.8.Gen
AegisLabHacktool.Win32.Gamehack.3!e
Endgamemalicious (high confidence)
EmsisoftAIT.Heur.Cottonmouth.8.Gen (B)
F-SecureHeuristic.HEUR/AGEN.1134165
Invinceaheuristic
SophosMal/Generic-S
Paloaltogeneric.ml
CyrenW32/AutoIt.IM.gen!Eldorado
AviraHEUR/AGEN.1134165
MAXmalware (ai score=87)
ArcabitAIT.Heur.Cottonmouth.8.Gen
ZoneAlarmTrojan-Spy.Win32.Stealer.tej
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
Ad-AwareAIT.Heur.Cottonmouth.8.Gen
MalwarebytesSpyware.RedLineStealer.AutoIt
APEXMalicious
eGambitUnsafe.AI_Score_96%
FortinetW32/Autoit.OIY!tr.dldr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM10.2.E0EF.Malware.Gen

How to remove Spyware.RedLineStealer.AutoIt?

Spyware.RedLineStealer.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment