Trojan

Trojan.AutoIt.Blocker.A (file analysis)

Malware Removal

The Trojan.AutoIt.Blocker.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoIt.Blocker.A virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings
  • Generates some ICMP traffic
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ddl.serveftp.com

How to determine Trojan.AutoIt.Blocker.A?


File Info:

crc32: 0647F4C7
md5: dd81531815ffbc70ec2be9e7213a4e5c
name: DD81531815FFBC70EC2BE9E7213A4E5C.mlw
sha1: 918421b805e782ab1d7a19121043f82eaf959c98
sha256: 194739d84e81db630a2a5c890dd560d088d829959239829efc86221640a8d99a
sha512: 6ee2eb345a42c6b65e31e47d93c7a77b77dcdac09ba4e330c5da3492c2cdf65b3454195532d712365ddcfdab2206c0d5a10841d55ee443ac9c776bff8214d5e2
ssdeep: 24576:pRmJkcoQricOIQxiZY1iaC1p1Zk3bGfAL0fUeAFkU1rqsWuw6No2:mJZoQrbTFZY1iaC1p1Zk3bGIu1AuU1r5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Trojan.AutoIt.Blocker.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Autoit.lzM7
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.57571
ClamAVWin.Dropper.Autoit-6574647-0
CAT-QuickHealTrojan.AutoIt.Blocker.A
ALYacTrojan.GenericKD.45064874
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.10607
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaWorm:Win32/Scrarev.00e6565a
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
CyrenW32/Trojan.EGCM-4995
SymantecTrojan.Zbot
ESET-NOD32Win32/Autoit.Injector.E
APEXMalicious
AvastWin32:AutoIt-CER [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Autoit.ckc
BitDefenderTrojan.GenericKD.45064874
NANO-AntivirusTrojan.Script.Autoit.duieeb
MicroWorld-eScanTrojan.GenericKD.45064874
TencentWin32.Trojan.Autoit.Wugv
Ad-AwareTrojan.GenericKD.45064874
SophosMal/Generic-R + Troj/AutoIt-YS
ComodoMalware@#2ezo3ioq4sq8s
BitDefenderThetaAI:Packer.A65E35CA16
VIPRETrojan.Win32.AutoIt.ysb (v)
TrendMicroTROJ_RANSOM_DD300507.UVPA
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.dd81531815ffbc70
EmsisoftTrojan.GenericKD.45064874 (B)
JiangminTrojan.Autoit.fygq
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Scrarev.A
ZoneAlarmTrojan.Win32.Autoit.ckc
GDataTrojan.GenericKD.45064874
McAfeeTrojan-FGGM!DD81531815FF
MAXmalware (ai score=80)
VBA32Trojan.Autoit.F
MalwarebytesMalware.AI.4049056807
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_RANSOM_DD300507.UVPA
IkarusWorm.Win32.AutoIt
MaxSecureTrojan.Autoit.AZA
FortinetW32/Blocker.CJFR!tr
AVGWin32:AutoIt-CER [Trj]
Paloaltogeneric.ml

How to remove Trojan.AutoIt.Blocker.A?

Trojan.AutoIt.Blocker.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment