Malware

Troj/AutoG-FE removal tips

Malware Removal

The Troj/AutoG-FE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/AutoG-FE virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

users.qzone.qq.com
ocsp.dcocsp.cn

How to determine Troj/AutoG-FE?


File Info:

crc32: 6DE06F55
md5: f117e5bc0d0e957bd8c731a84cfd9eed
name: F117E5BC0D0E957BD8C731A84CFD9EED.mlw
sha1: 8c6e17e56bbf51f9c4d6fef4ffcafcee31208471
sha256: 1287ca319b2b1756e401390615c9799a94191581dc6d08ac8538f9b432043676
sha512: e63e26ba98b05aeac88662e0c0496a570efef3ddf8a0d8bac567828257dafd553366d2fb99afdff7e9a5e1b6ad463fa68a8c3c44dba364df31005d29c7781644
ssdeep: 768:JzlaN7dGuGnV6BKFrtY9nLsQyQXwuZmpUPG9:Jz/uGnV6BKRtunIoAuZ9O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: SAGA Incorporated, Copyright (C) 1998
InternalName: DSplit
FileVersion: 1, 0, 0, 1
CompanyName:
ProductName: Dynamic splitter (demo)
ProductVersion: 1, 0, 0, 1
FileDescription: Dynamic splitter (demo)
OriginalFilename: DSplit.EXE
Translation: 0x0409 0x04b0

Troj/AutoG-FE also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan-Downloader ( 004df2461 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader18.59296
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Redosdru.19849
ALYacTrojan.GenericKD.30849707
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Farfli.13c
K7GWTrojan-Downloader ( 004df2461 )
Cybereasonmalicious.c0d0e9
BaiduWin32.Trojan-Downloader.Agent.jm
CyrenW32/Trojan.IM.gen!Eldorado
SymantecDownloader!gm
ESET-NOD32Win32/TrojanDownloader.Agent.BZI
ZonerTrojan.Win32.83819
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Downloader.Farfli-6453698-0
KasperskyBackdoor.Win32.Farfli.adnj
BitDefenderTrojan.GenericKD.30849707
NANO-AntivirusTrojan.Win32.Agent.dzjfom
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanTrojan.GenericKD.30849707
TencentMalware.Win32.Gencirc.10b0cde3
Ad-AwareTrojan.GenericKD.30849707
SophosTroj/AutoG-FE
ComodoBackdoor.Win32.Beaugrit.C@6l4u2b
BitDefenderThetaAI:Packer.B573042321
VIPRELooksLike.Win32.Uruasy.b!ag (v)
TrendMicroBKDR_ZEGOST.SM17
McAfee-GW-EditionTrojan-FIOM!F117E5BC0D0E
FireEyeGeneric.mg.f117e5bc0d0e957b
EmsisoftTrojan.GenericKD.30849707 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.asi
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1120591
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.1F4
MicrosoftTrojan:Win32/Itagomoko
GridinsoftTrojan.Win32.Agent.dg!s1
ArcabitTrojan.Generic.D1D6BAAB
GDataTrojan.GenericKD.30849707
TACHYONBackdoor/W32.Farfli.73828
AhnLab-V3Trojan/Win32.RL_Itagomoko.R365141
Acronissuspicious
McAfeeTrojan-FIOM!F117E5BC0D0E
MAXmalware (ai score=88)
VBA32BScope.TrojanDownloader.Dupzom
MalwarebytesMalware.AI.4006694808
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.SM17
RisingTrojan.Generic@ML.100 (RDMK:DkGJLM7fNnovCou72OCRbA)
YandexTrojan.GenAsa!cwu6i/B5tcc
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.BOZ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Troj/AutoG-FE?

Troj/AutoG-FE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment