Trojan

Trojan.Win32.Autoit.blz malicious file

Malware Removal

The Trojan.Win32.Autoit.blz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Autoit.blz virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Autoit.blz?


File Info:

crc32: 4F33EE18
md5: 7cad3bb3bde43c03c92ae772355a0920
name: 7CAD3BB3BDE43C03C92AE772355A0920.mlw
sha1: dc847a09b58164381519ef09ca20e1f35d4ed831
sha256: 8cee4e2387ddc23f5dda70d40e0d91aea3c9330c080442a09566516d290a290f
sha512: 31222829af529b874ae2e783a5ef0b2472c13c45b57bde51e53ecdef125e7b2d6bb90fbb6fd9c95fe914596789c22da79d59e3d58390f6c3ecf949b007031596
ssdeep: 24576:IthEVaPqLwthEythEVaPqLwthEsthEVaN:sEVUc0EKEVUc0EAEVE
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Trojan.Win32.Autoit.blz also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 700000111 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.52876
ClamAVWin.Malware.Autoit-6981134-0
CAT-QuickHealTrojan.AutoIt.Pistolar.A
McAfeeGenericRXHC-HT!7CAD3BB3BDE4
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.152520
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 700000111 )
Cybereasonmalicious.3bde43
BaiduAutoIt.Worm.Agent.a
CyrenW32/AutoIt.SG.gen!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/Autoit.HZ
APEXMalicious
AvastAutoIt:Agent-DP [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Autoit.blz
BitDefenderTrojan.GenericKD.47235340
NANO-AntivirusTrojan.Script.AutoIt.dbycns
MicroWorld-eScanTrojan.GenericKD.47235340
Ad-AwareTrojan.GenericKD.47235340
SophosML/PE-A + W32/AutoIt-QA
ComodoTrojWare.Win32.Autoit.n@4p0xzq
BitDefenderThetaAI:Packer.05DA809615
VIPRETrojan-Spy.Win32.Zbot.gen
McAfee-GW-EditionBehavesLike.Win32.Spyware.tc
FireEyeGeneric.mg.7cad3bb3bde43c03
EmsisoftTrojan.GenericKD.47235340 (B)
JiangminTrojan.MSIL.Zapchast.ag
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASSuf.23200
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.47235340
AhnLab-V3Win-Trojan/Autoit.305824
VBA32Worm.Autoit.Rush
MAXmalware (ai score=83)
PandaTrj/Autoit.gen
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
IkarusTrojan.Win32.Autoit
FortinetW32/Autoit.HZ!worm
AVGAutoIt:Agent-DP [Trj]

How to remove Trojan.Win32.Autoit.blz?

Trojan.Win32.Autoit.blz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment