Trojan

About “Trojan.AutoIt.CUH (B)” infection

Malware Removal

The Trojan.AutoIt.CUH (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoIt.CUH (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Exhibits behavior characteristic of Nanocore RAT
  • Collects information to fingerprint the system

Related domains:

bariecavale.ddns.net

How to determine Trojan.AutoIt.CUH (B)?


File Info:

crc32: AC29588A
md5: bf198db7b5ea841a9d8a80543d290f5f
name: BF198DB7B5EA841A9D8A80543D290F5F.mlw
sha1: 68654d3fa5ca5a195913cc8544fe803f79bb6b43
sha256: 0871149e18fd118597e0807d890c6a345909228fae16bb4037286894af4a0804
sha512: f458f91d82a38829ed1a1c67da9a4d34b6503745ca0dd73c465c5e7b8a63728df3db581b20f1221a942b2fe8cf6e317daf12849c525668018876e8419a6ac2cf
ssdeep: 24576:LmoO8it5+fZsZKykB+YY6RqU7OJ3BAUunssRtNkR:K4ZsZP2CjLWRts
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.AutoIt.CUH (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b68631 )
DrWebTrojan.Nanocore.427
CynetMalicious (score: 100)
ALYacTrojan.AutoIt.CUH
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004b68631 )
Cybereasonmalicious.7b5ea8
CyrenW32/S-e8958863!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32RAR/Agent.AZ
APEXMalicious
AvastFileRepMalware
ClamAVWin.Malware.Uztuby-6815912-0
KasperskyTrojan-Ransom.Win32.Blocker.lcde
BitDefenderTrojan.AutoIt.CUH
NANO-AntivirusTrojan.Win32.Blocker.ffabkw
MicroWorld-eScanTrojan.AutoIt.CUH
TencentWin32.Trojan.Blocker.Pgmr
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34692.fzZ@auRqoDhO
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.bf198db7b5ea841a
EmsisoftTrojan.AutoIt.CUH (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Agent.ubnih
eGambitUnsafe.AI_Score_99%
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.AutoIt.CUH
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.AutoIt.CUH
McAfeeArtemis!BF198DB7B5EA
MAXmalware (ai score=97)
MalwarebytesMalware.AI.1564431414
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.3f1c93
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan.AutoIt.CUH (B)?

Trojan.AutoIt.CUH (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment