Trojan

Trojan.Autoit.Agent.ND information

Malware Removal

The Trojan.Autoit.Agent.ND is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Autoit.Agent.ND virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Autoit.Agent.ND?


File Info:

name: 7826892C8DD50A8C8C72.mlw
path: /opt/CAPEv2/storage/binaries/ae342f561a0a49a83c1d0aff52c0b4e8cd25b2914c9013862b47c569b0593181
crc32: 83313A62
md5: 7826892c8dd50a8c8c72450c7572643e
sha1: 2590d7e105b6bd540513130dbca05d6ee7e00f38
sha256: ae342f561a0a49a83c1d0aff52c0b4e8cd25b2914c9013862b47c569b0593181
sha512: d339f0c10d576717bba9e005548fa5f83939125b9662302741c41d9fb7baa462348e5ad5d8499a7b2f48ba467f134cc526042f16a303ad51bc6210bffa6264eb
ssdeep: 24576:pyJz1/u2wwEhD0YYZxoWaZLJN2tTZcZ530DJvadJukvIi0p/wNkttYuX8sCjHoQ:e1VwlD0ZZeWaZVccZ52af5SStuX8r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B185E02273DDC361CB729173BD69B7106E7F78610638B9672F980D79AE1027212CD6A3
sha3_384: f0f730024f05da66db9a21b030a260f74dc71a6a1cf5fa2dd5f4d40428baaa860f4ebdbba8d3642b4889e69dd4537db5
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2016-11-21 02:13:49

Version Info:

Translation: 0x0809 0x04b0

Trojan.Autoit.Agent.ND also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Autoit.Agent.ND
FireEyeGeneric.mg.7826892c8dd50a8c
CAT-QuickHealTrojan.Generic.A
ALYacAIT:Trojan.Autoit.DDR
CylanceUnsafe
K7AntiVirusTrojan ( 005642691 )
K7GWTrojan ( 005642691 )
Cybereasonmalicious.c8dd50
BitDefenderThetaAI:Packer.480A8D7C1A
ESET-NOD32a variant of Win32/Injector.Autoit.CPP
APEXMalicious
AvastAutoIt:Stealer-E [Trj]
ClamAVWin.Dropper.Autoit-6688753-0
KasperskyHEUR:Trojan-Dropper.Script.Generic
BitDefenderTrojan.Autoit.Agent.ND
NANO-AntivirusTrojan.Script.Agent.fpgbat
Ad-AwareTrojan.Autoit.Agent.ND
EmsisoftTrojan.Autoit.Agent.ND (B)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
SophosTroj/AutoIt-BVD
GDataAIT:Trojan.Autoit.DDR (2x)
eGambitUnsafe.AI_Score_85%
ArcabitAIT:Trojan.Autoit.DDR
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!7826892C8DD5
MAXmalware (ai score=88)
MalwarebytesBackdoor.NanoCore
AVGAutoIt:Stealer-E [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Autoit.Agent.ND?

Trojan.Autoit.Agent.ND removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment