Trojan

Trojan.Win32.Autoit.acgrw malicious file

Malware Removal

The Trojan.Win32.Autoit.acgrw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Autoit.acgrw virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers

How to determine Trojan.Win32.Autoit.acgrw?


File Info:

name: 9EFC322088B957AA66D2.mlw
path: /opt/CAPEv2/storage/binaries/a308bba02b46d1566caa68d5d6df57ce942602d081ca9f1a35e030f8a8dd72af
crc32: 6D524811
md5: 9efc322088b957aa66d25dfdfa189d59
sha1: 9db0e1f073cd8f3ecd7880f91bc5cf55de362358
sha256: a308bba02b46d1566caa68d5d6df57ce942602d081ca9f1a35e030f8a8dd72af
sha512: b3d9c20ade1c754c43583be88fd9a873d411a63f211b9764458c0af5b6d24d131af05efa0d2adceadaf57898e073b08e47b674d7b4a49108ea2ba43ce65055b5
ssdeep: 24576:V4lavt0LkLL9IMixoEgea1pSDykMDV13v7653wuBJQ9V3I/q9MmCS:skwkn9IMHea1OqDvf76Z5JQ9caPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E075E00273EDC3A0C3729233BE66B765AE7B7C2506A1F59B2FD5093DA920121521F673
sha3_384: 4e460264713641d8b66c9e1b8d1a0e0cb19aa642242fd790969d290fa6971a6b23f0d3f0bca7bec10ab7e3e3a3363f96
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2022-01-19 19:39:54

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Autoit.acgrw also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38872841
FireEyeGeneric.mg.9efc322088b957aa
McAfeeArtemis!9EFC322088B9
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
CyrenW32/AutoIt.SM.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-9780500-0
KasperskyTrojan.Win32.Autoit.acgrw
BitDefenderTrojan.GenericKD.38872841
AvastWin32:Malware-gen
TencentWin32.Trojan.Autoit.Hzno
Ad-AwareTrojan.GenericKD.38872841
EmsisoftTrojan.GenericKD.38872841 (B)
ComodoApplicUnwnt@#2q1bxrxul4qbf
TrendMicroTROJ_GEN.F0CBC0UBB22
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
SophosMal/Generic-S
GDataTrojan.GenericKD.38872841
WebrootW32.Trojan.Gen
AviraDR/AutoIt.Gen8
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4192480
VBA32Trojan.Autoit
ALYacTrojan.GenericKD.38872841
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3616357514
TrendMicro-HouseCallTROJ_GEN.F0CBC0UBB22
eGambitGeneric.Malware
FortinetAutoIt/Agent.OZU!tr
AVGWin32:Malware-gen
Cybereasonmalicious.088b95
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Autoit.acgrw?

Trojan.Win32.Autoit.acgrw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment