Trojan

Trojan.Agent.AutoIt removal

Malware Removal

The Trojan.Agent.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.AutoIt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (10 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
bit.ly
virals.ws
www.bing.com
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org
www.googletagmanager.com
native.propellerclick.com

How to determine Trojan.Agent.AutoIt?


File Info:

crc32: CF739EE9
md5: 2e2ef69f54a91b00b482b51be263b045
name: sexya.sfx.exe
sha1: c4bcca77c42fd482058ff82fc5be31137a237fc7
sha256: 780dc8799b769bf70c5e725997c6a4d7865c635024d714385d10645e20426b47
sha512: d8feb596ac3098c9965269839887aa800b391188f77d0dde8df711da3a5e613b70f6ff47884ba6510765ab8bcada5086d1b7149bc33156028bfd42e019917999
ssdeep: 12288:ihjQ7GXN8fVsgQ137rCg+DezSs7XHdTkxd9wox:/GXN89Qreg+Dez1JAOox
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.AutoIt also known as:

MicroWorld-eScanTrojan.GenericKD.42334932
FireEyeTrojan.GenericKD.42334932
CAT-QuickHealTrojan.Multi
Qihoo-360Win32/Trojan.88a
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.4!c
K7AntiVirusSpyware ( 004c98ff1 )
BitDefenderTrojan.GenericKD.42334932
K7GWSpyware ( 004c98ff1 )
Cybereasonmalicious.7c42fd
TrendMicroTROJ_GEN.R023C0PAV20
CyrenW32/Trojan.LGCV-6451
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R023C0PAV20
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42334932
KasperskyTrojan.Win32.Agent.xadcra
AlibabaTrojanClicker:Win32/Autoit.b1e0b742
NANO-AntivirusTrojan.Win32.Autoit.gzasrv
Ad-AwareTrojan.GenericKD.42334932
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1000304
McAfee-GW-EditionRDN/Generic.dx
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.42334932 (B)
AviraHEUR/AGEN.1000304
MAXmalware (ai score=87)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D285FAD4
ZoneAlarmTrojan.Win32.Agent.xadcra
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C2536269
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.42334932
MalwarebytesTrojan.Agent.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrojanClicker.Autoit.NEJ
TencentWin32.Trojan.Agent.Hrzi
IkarusTrojan.Win32.TrojanClicker
FortinetW32/Autoit.DJ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan.Agent.AutoIt?

Trojan.Agent.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment