Trojan

Trojan.Qulab.AutoIt.Generic malicious file

Malware Removal

The Trojan.Qulab.AutoIt.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Qulab.AutoIt.Generic virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.telegram.org
ipapi.co

How to determine Trojan.Qulab.AutoIt.Generic?


File Info:

crc32: DDC76C16
md5: d4791630ca32006bbbcaa1800f53810e
name: installer.exe
sha1: 652ec510d94dfde06d28509be993bf440b97ed6c
sha256: 068fab19a666c345c3a746281690383a6a3551453a059c5c924e156152d6c202
sha512: 6b75cdfaa17e55d22ae0c9074505b0298ef4cdc7b5db1922f93aebbd39b1bc99bb21863d28b4d0a0c9e23b29b97aa8d49f7d8e5e0cf2d90959fb48ae01d42a38
ssdeep: 49152:Ph+ZkldoPK8Ya+bz5rcWEmyi60QijGLc3PShSY886fynFkzOhFYg0NNT+lxkGvf:Y2cPK8Qz5v560QijXOBFkGUTJGv0E6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: getmac.exe
FileVersion: 4.6.8.2
CompanyName: x412x435x431-x43fx43bx430x442x444x43ex440x43cx430 Microsoft Edge
Comments: UvTmrqnCd7RsHMAiNaY8YlFo8CpzqTPDivKzhBEPmO7MbYF5vDgtfvrYe7BUV3I17gREYkU3
ProductVersion: 4.6.8.2
FileDescription: NetBIOS Interface Library
OriginalFilename: getmac.exe
Translation: 0x0809 0x04b0

Trojan.Qulab.AutoIt.Generic also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Trojan.Heur.AutoIT.2
FireEyeGeneric.mg.d4791630ca32006b
McAfeeArtemis!D4791630CA32
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Trojan.Heur.AutoIT.2
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTrojan.Win32.CRYPTINJECT.SMB
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastScript:SNH-gen [Trj]
ClamAVWin.Malware.Agen-6962462-0
GDataGen:Trojan.Heur.AutoIT.2
KasperskyHEUR:Trojan-PSW.Win32.Masqulab.b
AlibabaTrojanPSW:Win32/Masqulab.c9e5efa9
AegisLabHacktool.Win32.Gamehack.3!e
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.Heur.AutoIT.2 (B)
F-SecureHeuristic.HEUR/AGEN.1100011
DrWebTrojan.PWS.Stealer.27517
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.wc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Autoit
AviraHEUR/AGEN.1100011
MAXmalware (ai score=81)
ArcabitTrojan.Heur.AutoIT.2
ZoneAlarmHEUR:Trojan-PSW.Win32.Masqulab.b
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
Ad-AwareGen:Trojan.Heur.AutoIT.2
MalwarebytesTrojan.Qulab.AutoIt.Generic
ESET-NOD32a variant of Win32/Packed.AutoIt.UL
TrendMicro-HouseCallTrojan.Win32.CRYPTINJECT.SMB
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Packed.OH!tr
BitDefenderThetaAI:Packer.44866B6B18
AVGScript:SNH-gen [Trj]
Cybereasonmalicious.0ca320
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.PSW.0d3

How to remove Trojan.Qulab.AutoIt.Generic?

Trojan.Qulab.AutoIt.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment