Trojan

What is “Trojan.Win32.Autoit.accfw”?

Malware Removal

The Trojan.Win32.Autoit.accfw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Autoit.accfw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Autoit.accfw?


File Info:

crc32: 56E0B5DD
md5: 0393e4c334723d1107507ef544f88af2
name: Onekey_2020.exe
sha1: 8be33cd0734f26da915c68a3fa0aa643d8bf9ae9
sha256: 596495dbe43509496fef5ac3fd286110aee52f0f8ad82324e8ab651890193f87
sha512: 7dc6b56620cc2e1963c274fb903c2b3fb5b10e07c57d5338abe456f4e17687315eab8e419b79c6017ac4faedda3fbd407ee298444f3446d784cc4189b612ddd9
ssdeep: 196608:C9Bgv+5sUjWKowkwkDGxmT12PLJuj1s1XcuxapPfWCWgd0UaxW2x7k9:C9Bgm5sa3Dkn2wTuspPfWCRta02x7g
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: x96e8x6797x6728x98cex88c5x673ax5927x5e08
internalname: ylmf.exe
FileVersion: 3.1.0.0
Comments: x96e8x6797x6728x98cex88c5x673ax5927x5e08
ProductName: x96e8x6797x6728x98cex88c5x673ax5927x5e08
ProductVersion: 3.1.0.0
FileDescription: x96e8x6797x6728x98cex88c5x673ax5927x5e08
OriginalFilename: ylmf.exe
Translation: 0x0804 0x04b0

Trojan.Win32.Autoit.accfw also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33461764
CMCVirus.Win32.Sality!O
McAfeeArtemis!0393E4C33472
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055e8911 )
BitDefenderTrojan.GenericKD.33461764
K7GWTrojan ( 0055e8911 )
TrendMicroTrojan.Win32.WACATAC.THCOCBO
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.33461764
KasperskyTrojan.Win32.Autoit.accfw
AlibabaTrojan:Win32/Autoit.66fb63f5
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan.Autoit.Eoh
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33461764 (B)
F-SecureHeuristic.HEUR/AGEN.1043842
DrWebTrojan.DownLoader33.6201
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Injector.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.0393e4c334723d11
SophosMal/Generic-S
IkarusTrojan.Win32.Autoit
CyrenW32/Trojan.JHDO-8963
JiangminRiskTool.Miner.fl
AviraHEUR/AGEN.1043842
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D1FE9604
ZoneAlarmTrojan.Win32.Autoit.accfw
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.Banload.C1347382
Acronissuspicious
VBA32Trojan.Downloader
ALYacTrojan.GenericKD.33461764
Ad-AwareTrojan.GenericKD.33461764
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Autoit.NBM suspicious
TrendMicro-HouseCallTrojan.Win32.WACATAC.THCOCBO
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Autoit
BitDefenderThetaGen:NN.ZexaF.34096.@pxaaanp67nj
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Win32.Autoit.accfw?

Trojan.Win32.Autoit.accfw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment