Trojan

About “Trojan-Downloader.Win32.Autoit.vtz” infection

Malware Removal

The Trojan-Downloader.Win32.Autoit.vtz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Autoit.vtz virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Autoit.vtz?


File Info:

crc32: FD20D310
md5: a37adfea35439fadf5c058c62a7bd7b0
name: Test.jpg
sha1: 81955f445ce2d21ef4b21405f98ec39f9906a6b8
sha256: cc6b80a682438f2dd7ce3ab3bb9fb3dcd20b3fe96dcb33ec7b00e5528328b13e
sha512: e5e79866c8164536d8dfb0f91b7575c6dc3a52407a8e9fec22ceac104aa15f1dc9f6f273d802c98ce61d8b2acaf671a16f6583914f8a8a3b3af6628a5e3855b7
ssdeep: 24576:5AHnh+eWsN3skA4RV1Hom2KXMmHaqra5:Ah+ZkldoPK8Yaqk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Downloader.Win32.Autoit.vtz also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.DownLoader30.28459
MicroWorld-eScanTrojan.GenericKD.32598144
FireEyeGeneric.mg.a37adfea35439fad
Qihoo-360HEUR/QVM10.2.A42B.Malware.Gen
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 005599f81 )
BitDefenderTrojan.GenericKD.32598144
CrowdStrikewin/malicious_confidence_60% (W)
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.32598144
KasperskyTrojan-Downloader.Win32.Autoit.vtz
AlibabaTrojanDownloader:Win32/Autoit.1de9f0ca
NANO-AntivirusTrojan.Win32.Autoit.gecxvh
AegisLabHacktool.Win32.Gamehack.3!e
AvastWin32:Trojan-gen
RisingTrojan.PSRunner/Autoit!1.C292 (CLASSIC)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#q7s5xkyeyjz7
F-SecureTrojan.TR/Dldr.Autoit.ohxxj
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftTrojan.GenericKD.32598144 (B)
AviraTR/Dldr.Autoit.ohxxj
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Generic.D1F16880
ZoneAlarmTrojan-Downloader.Win32.Autoit.vtz
ALYacTrojan.GenericKD.32598144
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.32598144
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.OUX
TencentWin32.Trojan-downloader.Autoit.Llha
IkarusTrojan-Downloader.Win32.AutoIt
eGambitUnsafe.AI_Score_98%
FortinetW32/Autoit.OUX!tr.dldr
AVGWin32:Trojan-gen
Cybereasonmalicious.45ce2d
PandaTrj/CI.A
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan-Downloader.Win32.Autoit.vtz?

Trojan-Downloader.Win32.Autoit.vtz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment