Malware

Troj/AutoIt-CMZ removal

Malware Removal

The Troj/AutoIt-CMZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/AutoIt-CMZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • Creates a copy of itself
  • Creates known Remcos mutexes
  • Creates known Remcos registry keys
  • Anomalous binary characteristics

How to determine Troj/AutoIt-CMZ?


File Info:

name: 92A33E87520848EA7418.mlw
path: /opt/CAPEv2/storage/binaries/e051910d20871f96f92422d46152a75360aeacf3193a6b856f0193113d75b5df
crc32: A8BDAE2A
md5: 92a33e87520848ea7418d156e55d484b
sha1: b4169a3f999e14d7dd9d34307862b89316a655f6
sha256: e051910d20871f96f92422d46152a75360aeacf3193a6b856f0193113d75b5df
sha512: f1db4e59acbba92491a2a5cb2a89f83a710f33c0426808f58c38ab54bd7b166f74b186cd8fc22a7821fd0b0be4cb68d60731ef5f25590d925d5e1c687786c935
ssdeep: 24576:QAHnh+eWsN3skA4RV1Hom2KXFmIalKCc9GS59:Hh+ZkldoPK1XalKCc9n9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178259D0273D1C036FFABA2739B6AF24556BD79354123852F13981DB9BD701B2263E623
sha3_384: fc46ce060b14027f4cc5d98805863e4cd446871363b5a4a445f218d8bdef8993c0e58d8f8ba0e7e6861ba9970a31d936
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-30 10:20:13

Version Info:

Translation: 0x0809 0x04b0

Troj/AutoIt-CMZ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.41759
MicroWorld-eScanTrojan.GenericKD.32026646
FireEyeGeneric.mg.92a33e87520848ea
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
McAfeeTrojan-AitInject.aq
CylanceUnsafe
K7AntiVirusTrojan ( 0054f1021 )
K7GWTrojan ( 0054f1021 )
Cybereasonmalicious.752084
BitDefenderThetaAI:Packer.9A3D7CD617
VirITTrojan.Win32.AutoIT.CGKK
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.DZK
ClamAVWin.Malware.Remcos-6985942-1
KasperskyTrojan-Downloader.Win32.AutoIt.aop
BitDefenderTrojan.GenericKD.32026646
NANO-AntivirusTrojan.Script.Downloader.iuwddd
AvastAutoIt:Injector-JF [Trj]
TencentMalware.Win32.Gencirc.10b4d525
Ad-AwareTrojan.GenericKD.32026646
EmsisoftTrojan.GenericKD.32026646 (B)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
SophosTroj/AutoIt-CMZ
IkarusTrojan.Autoit
GDataTrojan.GenericKD.32026646
AviraDR/AutoIt.Gen8
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASCommon.151
ArcabitTrojan.Generic.D1E8B016
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
VBA32Trojan.Autoit.F
ALYacTrojan.GenericKD.32026646
MalwarebytesTrojan.MalPack.Generic
APEXMalicious
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
MaxSecureWin.MxResIcn.Heur.Gen
FortinetAutoIt/Injector.DZH!tr
AVGAutoIt:Injector-JF [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Troj/AutoIt-CMZ?

Troj/AutoIt-CMZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment