Trojan

Trojan-Dropper.Win32.Autit.nki malicious file

Malware Removal

The Trojan-Dropper.Win32.Autit.nki is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Autit.nki virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests information related to installed mail clients

How to determine Trojan-Dropper.Win32.Autit.nki?


File Info:

crc32: AE690677
md5: 60bb2e67cb8ec2034955c4474583a009
name: bigimulla.exe
sha1: bcbd0eb56a012af343da2b8ff905a8f7dc97da5f
sha256: c41740d0b885bfd84d2f854894ab00a9a9654c4fb5a16b14b5225a839b3dd831
sha512: be3cedf72c7b349d040e42ab7ebb3b5d80ccf2955412aa1cdb06709351857f4b1fb2be8d080b8686d0760583d58ac120eccbbb83dea5834485d71d9863883b00
ssdeep: 49152:Qu0c++OCvkGs9FaaOTtj6x6SqrXExzjbQsHY:nB3vkJ9C64S+ubQsH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: sihost
CompanyName: SecEdit
ProductName: AuthFWSnapin
ProductVersion: 453, 794, 358, 832
FileDescription: ClipRenew
OriginalFilename: WinMgmt.exe
Translation: 0x0000 0x04b0

Trojan-Dropper.Win32.Autit.nki also known as:

MicroWorld-eScanTrojan.GenericKD.42336214
FireEyeTrojan.GenericKD.42336214
Qihoo-360Generic/Trojan.72b
McAfeeArtemis!60BB2E67CB8E
CylanceUnsafe
AegisLabTrojan.Win32.AutoIT.4!c
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.GenericKD.42336214
Cybereasonmalicious.56a012
TrendMicroTROJ_GEN.R002C0TB320
F-ProtW32/AutoIt.NS.gen!Eldorado
SymantecPacked.Generic.548
TrendMicro-HouseCallTROJ_GEN.R002C0TB320
GDataTrojan.GenericKD.42336214
KasperskyTrojan-Dropper.Win32.Autit.nki
AlibabaTrojan:Win32/AutoitU.ali2000008
APEXMalicious
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Ad-AwareTrojan.GenericKD.42336214
SophosMal/Generic-S
F-SecureTrojan.TR/Autoit.hrhxd
DrWebTrojan.AutoIt.709
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42336214 (B)
CyrenW32/AutoIt.NS.gen!Eldorado
AviraTR/Autoit.hrhxd
MAXmalware (ai score=83)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D285FFD6
ZoneAlarmTrojan-Dropper.Win32.Autit.nki
MicrosoftTrojan:Win32/Predator.BC!MTB
AhnLab-V3Trojan/Win32.AutoInj.R279467
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.Autoit.FAE
IkarusWin32.Outbreak
FortinetAutoIt/Injector.EZY!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Dropper.Win32.Autit.nki?

Trojan-Dropper.Win32.Autit.nki removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment