Trojan

Trojan.Script.AutoIt malicious file

Malware Removal

The Trojan.Script.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Script.AutoIt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkver.jxvinhvien.com

How to determine Trojan.Script.AutoIt?


File Info:

crc32: 70188959
md5: 3c5adbfad4c326efb083c56f17f18b16
name: au.exe
sha1: 3593fa91131a2a100419992f7e0272440e7106ee
sha256: 2deea9df8211b13701a6afe30a0fb931485394a5c51c652677ed860ea75355f9
sha512: 4358a5ca1f1f8a982b95455e1f9c771ad0619cae32c492d7fbd8851354ba04e0c1af81f4c77e404cdc3fd5e83b12d9de2742ed8276329ada4456f21d4446d271
ssdeep: 24576:0AHnh+eWsN3skA4RV1Hom2KXMmHafbWdTwtL2JRxSS/zV5JvVINd5:Dh+ZkldoPK8YaadUL2pSYzVvqt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Script.AutoIt also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42122307
FireEyeGeneric.mg.3c5adbfad4c326ef
Qihoo-360Win32/Trojan.Downloader.06d
McAfeeArtemis!3C5ADBFAD4C3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42122307
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ad4c32
TrendMicroTROJ_GEN.R015C0WKR19
F-ProtW32/Nymeria.E.gen!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.42122307
KasperskyTrojan-Downloader.Win32.Agent.xxzbyt
AegisLabTrojan.Win32.Agent.a!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42122307 (B)
ComodoMalware@#8lp2qaalisan
F-SecureTrojan.TR/Autoit.osqam
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
IkarusTrojan-PWS.Win32.OnLineGames
CyrenW32/Nymeria.E.gen!Eldorado
AviraTR/Autoit.osqam
MAXmalware (ai score=96)
ArcabitTrojan.Generic.D282BC43
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzbyt
ALYacTrojan.GenericKD.42122307
Ad-AwareTrojan.GenericKD.42122307
MalwarebytesTrojan.Script.AutoIt
TrendMicro-HouseCallTROJ_GEN.R015C0WKR19
TencentWin32.Trojan-downloader.Agent.Llhq
YandexTrojan.AvsArher.bS970C
eGambitUnsafe.AI_Score_96%
FortinetW32/Autoit.ACBDE!tr
BitDefenderThetaAI:Packer.3E54863916
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Script.AutoIt?

Trojan.Script.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment