Malware

Troj/Autoit-CYE (file analysis)

Malware Removal

The Troj/Autoit-CYE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Autoit-CYE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Troj/Autoit-CYE?


File Info:

crc32: 0B849143
md5: 314e1e479f9749b8be983098a64387c4
name: 02-27-20.exe
sha1: 0e37ce11260853f7835aab1788ecdb90e269edb8
sha256: 0a1f29f107e9c91f6db74ed6aad68275f234531f2f6f2f280d88178a14d4a39f
sha512: 316bcc8ba89dbb4b5475be010459a860f3e94aaa89213b52d487906ae564cd49c3c1e8641bd4c8a2d45110fdc368efd64ecc68f69de5091fe855aefcb3153495
ssdeep: 49152:pu0c++OCvkGs9Falr3zuQneNPij7eXs3g7leUe0Y:cB3vkJ9y3pnSPZXsOde0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Troj/Autoit-CYE also known as:

MicroWorld-eScanTrojan.GenericKD.33417353
FireEyeGeneric.mg.314e1e479f9749b8
CAT-QuickHealTrojan.Bsymem
Qihoo-360Generic/HEUR/QVM10.2.8C55.Malware.Gen
ALYacTrojan.GenericKD.33417353
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33417353
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.126085
TrendMicroTrojan.AutoIt.WACATAC.USXVPBS20
F-ProtW32/AutoIt.NS.gen!Eldorado
SymantecPacked.Generic.548
TrendMicro-HouseCallTrojan.AutoIt.WACATAC.USXVPBS20
AvastScript:SNH-gen [Trj]
GDataTrojan.GenericKD.33417353
KasperskyTrojan.Win32.Bsymem.per
AlibabaTrojan:Win32/autoit.ali2000008
NANO-AntivirusTrojan.Win32.Bsymem.hcrsnm
ViRobotTrojan.Win32.Z.Autoit.1933824.A
AegisLabTrojan.Win32.AutoIt.4
TencentWin32.Trojan.Bsymem.Lgtq
Ad-AwareTrojan.GenericKD.33417353
SophosTroj/Autoit-CYE
F-SecureTrojan.TR/Autoit.pgzfk
DrWebTrojan.AutoIt.756
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.33417353 (B)
APEXMalicious
CyrenW32/AutoIt.NS.gen!Eldorado
WebrootW32.Trojan.AutoIt.WACATAC.USXVP
AviraTR/Autoit.pgzfk
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FDE889
ZoneAlarmTrojan.Win32.Bsymem.per
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AhnLab-V3Trojan/AU3.Wacatac.S1079
McAfeeArtemis!314E1E479F97
MAXmalware (ai score=100)
VBA32Trojan.Skeeyah
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FCZ
IkarusTrojan.Autoit
eGambitUnsafe.AI_Score_93%
FortinetAutoIt/Injector.EZG!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Troj/Autoit-CYE?

Troj/Autoit-CYE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment