Trojan

Trojan.AutoItScript removal

Malware Removal

The Trojan.AutoItScript is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoItScript virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.AutoItScript?


File Info:

name: F6FF79BAEEB642354391.mlw
path: /opt/CAPEv2/storage/binaries/b9b2a7a0fff1d3aec0403706a241150d1635e875596409a97245f69404139ef1
crc32: 266BC2A3
md5: f6ff79baeeb642354391aa39a907d681
sha1: 77a9336fd61c7b563dc76813a9bca3364f768f0b
sha256: b9b2a7a0fff1d3aec0403706a241150d1635e875596409a97245f69404139ef1
sha512: 0de3827f31a68218955b583ed654e74c8bdf8559e50490f952e2c3ed6aa9fd4185eed9ba1b89b9caf308395042acc7b36fd68bf89fe649e58d7361f4624922d7
ssdeep: 98304:c2cPK8kg6xkcJ26S4K1Ex/GI9MNX0w6aKUUrudoqkVeqzG:HCKE6rJfSl1Ex/GI9WEw6aBUttVg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D46221273E1D036FFA692739B19B60546BDB8654233C52F13981EB9BCB01B2267D723
sha3_384: 1a558bc546c9453543b58fc3a25f0ebac8ee6b0f288e36103903112837630dbfa2bdd0b25e8021af09f38c8118270812
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-12-01 13:57:55

Version Info:

Translation: 0x0809 0x04b0

Trojan.AutoItScript also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47591902
FireEyeGeneric.mg.f6ff79baeeb64235
McAfeeArtemis!F6FF79BAEEB6
CylanceUnsafe
Cybereasonmalicious.fd61c7
KasperskyVHO:Trojan.Win32.AutoItScript.gen
BitDefenderTrojan.GenericKD.47591902
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47591902
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.47591902 (B)
GDataTrojan.GenericKD.47591902
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
VBA32Trojan.AutoItScript
ALYacTrojan.GenericKD.47591902
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen

How to remove Trojan.AutoItScript?

Trojan.AutoItScript removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment