Trojan

Trojan.AutoRun.AutoIt removal guide

Malware Removal

The Trojan.AutoRun.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoRun.AutoIt virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.AutoRun.AutoIt?


File Info:

name: 470C9B7AD7C92D0814EB.mlw
path: /opt/CAPEv2/storage/binaries/bff41e4570eedce39536faed262a79658b40bc4387fcaa6543d559ab05046a82
crc32: A665B344
md5: 470c9b7ad7c92d0814eb4eb939cc39ea
sha1: 7c1ab96a6a3ba5ba0c3b09653cf84a50bab8e6d3
sha256: bff41e4570eedce39536faed262a79658b40bc4387fcaa6543d559ab05046a82
sha512: bcc312f4bd1747a8211662ca9348a95fcb5fca42cce4e2a60e825e10e629250b283b24cd33e0b5aab9763e4e48d897a3654147722a6cb7c293efef1a550234ea
ssdeep: 49152:nVg5tjVYOQyuiMBUsbHTodw3UHxLdtCb6Q0gTenU7:Vg5Ja7iMBUkTCw3gxLdG1TenU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DDB5F113678D8392C27182B3BE036B556F673D2956A1F5EF2F901D6EBD201320A4E637
sha3_384: d20ca388c0ab332226df976ed590c4da11682c41ef58b41a270fdc98af9c3309852f542881c70fa8f60d0d1849110dc3
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2014-11-07 20:50:00

Version Info:

CompanyName: 31/10/2014 06:14 p.m.
FileDescription: Carpeta de archivos
Translation: 0x0809 0x04b0

Trojan.AutoRun.AutoIt also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.BHAV
FireEyeGeneric.mg.470c9b7ad7c92d08
ALYacTrojan.Agent.BHAV
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.ad7c92
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.Autoit-6651610-0
KasperskyTrojan.Win32.Agent.neswjd
BitDefenderTrojan.Agent.BHAV
AvastAutoIt:Dropper-DJ [Trj]
Ad-AwareTrojan.Agent.BHAV
EmsisoftTrojan.Agent.BHAV (B)
DrWebTrojan.DownLoader22.46348
VIPRETrojan.Agent.BHAV
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusWorm.Win32.AutoRun
GDataTrojan.Agent.BHAV (2x)
MAXmalware (ai score=81)
ArcabitTrojan.Agent.BHAV
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C703706
Acronissuspicious
McAfeeW32/Worm-FYK!470C9B7AD7C9
VBA32Trojan.Autoit.Wirus
MalwarebytesTrojan.AutoRun.AutoIt
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaE.34806.HmW@auRPnnh
AVGAutoIt:Dropper-DJ [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.AutoRun.AutoIt?

Trojan.AutoRun.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment