Trojan

How to remove “Trojan-Dropper.Win32.Autoit.bpz”?

Malware Removal

The Trojan-Dropper.Win32.Autoit.bpz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Autoit.bpz virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

How to determine Trojan-Dropper.Win32.Autoit.bpz?


File Info:

crc32: E894A720
md5: fea64559bfc0a9382c02be8e150afcfa
name: FEA64559BFC0A9382C02BE8E150AFCFA.mlw
sha1: f605ceef61a8a8df7dc0535621ec6690b310568f
sha256: da5609a3da65a929dfcaff7d7c1f4512409f3048c4c9ce6b620275489c6c906a
sha512: 4d231142c80a11de347bbb107abf078bb5747ded45dccf6ea34a4fe2838af412d09d2e6d5b5c244bde84bbefd444a17e6a1f5c8dbb9efee5abbfafaec8afdd55
ssdeep: 12288:o4lsXvtCcmVVXzzn4PJAahPl/QEdIMiVbHydEIJnJWUgaT7AVRq9MmCS:o4lavt0LkLL9IMixoEgea/WRq9MmCS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan-Dropper.Win32.Autoit.bpz also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
ClamAVWin.Malware.Autoit-7130959-0
CAT-QuickHealTrojanPWS.AutoIt.Zbot.S
McAfeeDropper-AutoIt.e
CylanceUnsafe
SangforMalware
BitDefenderAIT:Trojan.Nymeria.81
Cybereasonmalicious.9bfc0a
ArcabitAIT:Trojan.Nymeria.81
BaiduWin32.Trojan-Dropper.Autoit.c
CyrenW32/AutoIt.EZ.gen!Eldorado
SymantecBackdoor.Ratenjay
APEXMalicious
AvastAutoIt:Runner-AN [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Autoit.bpz
NANO-AntivirusTrojan.Script.AutoIt.dcckyk
MicroWorld-eScanAIT:Trojan.Nymeria.81
Ad-AwareAIT:Trojan.Nymeria.81
EmsisoftAIT:Trojan.Nymeria.81 (B)
F-SecureHeuristic.HEUR/AGEN.1134155
DrWebTrojan.DownLoader11.33994
McAfee-GW-EditionBehavesLike.Win32.DownloaderAutoIt.ch
FireEyeGeneric.mg.fea64559bfc0a938
SophosML/PE-A + Troj/Autoit-BIF
IkarusTrojan-Dropper.Win32.Autoit
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1134155
MicrosoftTrojan:Win32/Fuerboos.D!cl
ZoneAlarmTrojan-Dropper.Win32.Autoit.bpz
GDataAIT:Trojan.Nymeria.81 (2x)
AhnLab-V3Dropper/RL.Autoit.R243146
BitDefenderThetaAI:Packer.4A7CAE7C15
ALYacAIT:Trojan.Nymeria.81
MAXmalware (ai score=86)
MalwarebytesBackdoor.Bladabindi.AutoIt
ESET-NOD32multiple detections
eGambitUnsafe.AI_Score_74%
FortinetW32/Autoit.AWL!tr
AVGAutoIt:Runner-AN [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM10.1.061F.Malware.Gen

How to remove Trojan-Dropper.Win32.Autoit.bpz?

Trojan-Dropper.Win32.Autoit.bpz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment