Trojan

Trojan-Downloader.Autoit (A) information

Malware Removal

The Trojan-Downloader.Autoit (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Autoit (A) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Attempts to execute a powershell command with suspicious parameter/s
  • Creates a hidden or system file
  • Attempts to create or modify system certificates

Related domains:

paste.ee

How to determine Trojan-Downloader.Autoit (A)?


File Info:

crc32: C65400D1
md5: ceb3a00c44f960e225822d61a6658533
name: upload_file
sha1: 86d819246f2bd19201b40003f930d27ff3cc8a8e
sha256: eb91d37691efff36f75fa0a08bcc716c87cd5180d5a7046694af87396a37f99a
sha512: 9c3c193c2e0d0d25b8ad224990e97920e15209a2fb2431647ef2a1992243039e5c5746613434f74e8fda839ff3cd194f410c5667411bc01c5910ff484f09430d
ssdeep: 24576:cAHnh+eWsN3skA4RV1Hom2KXMmHaHGAQ5:7h+ZkldoPK8YaHG/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Downloader.Autoit (A) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34388415
FireEyeGeneric.mg.ceb3a00c44f960e2
McAfeeArtemis!CEB3A00C44F9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056ab9f1 )
BitDefenderTrojan.GenericKD.34388415
K7GWTrojan-Downloader ( 0056ab9f1 )
Cybereasonmalicious.46f2bd
Invinceaheuristic
CyrenW32/AutoIt.SN.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Povertel.ayt
AlibabaTrojanDownloader:Win32/Povertel.3a507324
ViRobotTrojan.Win32.Z.Povertel.868864.D
RisingTrojan.PSRunner/Autoit!1.C834 (CLASSIC)
Ad-AwareTrojan.GenericKD.34388415
EmsisoftTrojan-Downloader.Autoit (A)
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1134154
TrendMicroTROJ_GEN.R002C0DHJ20
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.AutoIt
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1134154
MAXmalware (ai score=88)
MicrosoftTrojanDownloader:AutoIt/Povertel.G!MTB
ArcabitTrojan.Generic.D20CB9BF
ZoneAlarmTrojan.Win32.Povertel.ayt
GDataTrojan.GenericKD.34388415
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.OZR
ALYacTrojan.GenericKD.34388415
MalwarebytesTrojan.Downloader.AutoIt
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DHJ20
TencentWin32.Trojan.Povertel.Tcvr
eGambitUnsafe.AI_Score_93%
FortinetAutoIt/Povertel.AWH!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM10.2.5B47.Malware.Gen

How to remove Trojan-Downloader.Autoit (A)?

Trojan-Downloader.Autoit (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment