Trojan

How to remove “Trojan.Heur.AutoIT.17”?

Malware Removal

The Trojan.Heur.AutoIT.17 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.AutoIT.17 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.telegram.org
longlove.do.am
ipapi.co

How to determine Trojan.Heur.AutoIT.17?


File Info:

crc32: 02722D76
md5: 055a2686a3c78e862e643f054d7b0e58
name: gram.exe
sha1: 91b34ce63853b942e3fb1306bdaf925ef80d5d65
sha256: cf4b1d094666cf65812ede40cf21ff2d6882f5bba8988ad300669e2c3a563a47
sha512: 4d3148ed48f442f7c4ed9a40b53b1ecf03be79f64cb20678188d8bf0855431ea5600d1a30668a72a1eb11850b1e4a63fb883124ec2c73abdd91e99af310bb422
ssdeep: 49152:Ih+ZkldoPK8Ya7ym2HcHo8woc+G5p/852ZhUpb6PVb1alpg:p2cPK8YbHcI84l5phZ2yb1i
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sort.exe
FileVersion: 5.3.3.9
CompanyName: Windows USB Driver User Library
Comments: lTzYrxMv6i4KkPvo5qwKp6wb8A8UYu6edhVXfRCrTiqkUFWfVVxC52ZStSxcUTQF
ProductVersion: 5.3.3.9
FileDescription: x421x440x435x434x441x442x432x43e x43fx440x43ex432x435x440x43ax438 x43ex440x444x43ex433x440x430x444x438x438 (x41cx430x439x43ax440x43ex441x43ex444x442)
OriginalFilename: sort.exe
Translation: 0x0809 0x04b0

Trojan.Heur.AutoIT.17 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Trojan.Heur.AutoIT.17
FireEyeGeneric.mg.055a2686a3c78e86
Qihoo-360Win32/Trojan.PSW.0d3
McAfeeArtemis!055A2686A3C7
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.AutoIT.17
K7GWTrojan ( 700000111 )
Cybereasonmalicious.63853b
Invinceaheuristic
BitDefenderThetaAI:Packer.49B4C87719
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.Win32.CRYPTINJECT.SMB
AvastScript:SNH-gen [Trj]
ClamAVWin.Malware.Autoit-7013875-0
GDataGen:Trojan.Heur.AutoIT.17
KasperskyHEUR:Trojan-PSW.Win32.Masqulab.b
AlibabaTrojanPSW:Win32/Masqulab.8e68da98
AegisLabHacktool.Win32.Gamehack.3!e
TencentWin32.Trojan-qqpass.Qqrob.Duw
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.Heur.AutoIT.17 (B)
ComodoMalware@#q4y8yufwymh3
F-SecureHeuristic.HEUR/AGEN.1040377
DrWebTrojan.PWS.Stealer.27517
TrendMicroTrojan.Win32.CRYPTINJECT.SMB
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
APEXMalicious
CyrenW32/Trojan.NLQW-3609
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1040377
MicrosoftTrojan:AutoIt/Injector.J!ibt
ArcabitTrojan.Heur.AutoIT.17
ZoneAlarmHEUR:Trojan.Win32.Generic
MAXmalware (ai score=100)
Ad-AwareGen:Trojan.Heur.AutoIT.17
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.AutoIt.UI
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
IkarusTrojan.Win32.Autoit
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Packed.OH!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.Heur.AutoIT.17?

Trojan.Heur.AutoIT.17 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment