Malware

Troj/AutoIt-CLG (file analysis)

Malware Removal

The Troj/AutoIt-CLG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/AutoIt-CLG virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself

Related domains:

ginam2525.kro.kr

How to determine Troj/AutoIt-CLG?


File Info:

crc32: 08421641
md5: 6ee5fc59a1d7c232aecfbbaf4287a35e
name: 6EE5FC59A1D7C232AECFBBAF4287A35E.mlw
sha1: 62ecfa73330d1e0a98c538818dffeece611f2e8c
sha256: 0740ff92adebf32666b8be1b03ca66d0b99c8c9b2ce332480b26b202c54efb72
sha512: 5407024a72ad628e1da76a70ada18347cf782994d615db9f5a98032cd28e3d72458a4319572fde9deb5644f11abd2d232706762c09551eb06e14fac772671878
ssdeep: 12288:aYV6MorX7qzuC3QHO9FQVHPF51jgcNkeRG9FG:JBXu9HGaVHNkG+G
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: mtstocom
FileVersion: 783.135.470.865
CompanyName: MbaeParserTask
ProductName: SystemSettingsRemoveDevice
ProductVersion: 59.547.663.944
FileDescription: certreq
OriginalFilename: RdpSaProxy
Translation: 0x0409 0x04b0

Troj/AutoIt-CLG also known as:

Elasticmalicious (high confidence)
ClamAVWin.Malware.Autoit-6968584-1
FireEyeGeneric.mg.6ee5fc59a1d7c232
McAfeeArtemis!6EE5FC59A1D7
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
CyrenW32/AutoIt.JU.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Script.SAgent.gen
BitDefenderGen:Trojan.Heur.AutoIT.16
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
TencentMalware.Win32.Gencirc.11b0ff5d
Ad-AwareGen:Trojan.Heur.AutoIT.16
SophosTroj/AutoIt-CLG
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.DownLoader28.11777
InvinceaML/PE-A + Troj/AutoIt-CLG
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.gc
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
AviraDR/AutoIt.Gen8
Antiy-AVLGrayWare/Autoit.ShellCode.a
ArcabitTrojan.Heur.AutoIT.16
ZoneAlarmHEUR:Trojan.Win32.Autoit.gen
MicrosoftTrojan:MSIL/Bladabindi
AhnLab-V3Trojan/Win32.Stimilina.C3206305
Acronissuspicious
BitDefenderThetaAI:Packer.792E1D3017
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.Generic
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
YandexTrojan.AvsArher.bS9LKk
IkarusTrojan-Spy.HawkEye
FortinetAutoIt/Packed.OV!tr
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.9a1d7c

How to remove Troj/AutoIt-CLG?

Troj/AutoIt-CLG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment