Trojan

Trojan.Win32.AutoIt.bpv removal tips

Malware Removal

The Trojan.Win32.AutoIt.bpv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.AutoIt.bpv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.AutoIt.bpv?


File Info:

name: 8788716F6FD7402446C7.mlw
path: /opt/CAPEv2/storage/binaries/6572dcb4b691064ed518bf009c1191490dc57292cb1a0a4f7b5e4fe8c47fc89b
crc32: F7CD12CB
md5: 8788716f6fd7402446c7e9c41a136b19
sha1: 96acbf2f35ddd1a7de939dcf7c3f2634db761a03
sha256: 6572dcb4b691064ed518bf009c1191490dc57292cb1a0a4f7b5e4fe8c47fc89b
sha512: 60adb5e80f0eeeb66599ad04ccc7405596201ff6de9b576a68ee8a160c0832dd1d6288b18d9cadf7b887dd3cb860c82f48e4620287d6886a58bd13fae53f2e5f
ssdeep: 12288:ThkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNRTGMp+MsHd2qAyrrsLJ+d:ZRmJkcoQricOIQxiZY1WN0G+MsH5w+d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10325C012B5C590B6C2B323F19D7FF765993D793A0336C19B37C82A215E606412A3EB27
sha3_384: f3d74258b90d21e6b5639341aae1a8820ae01e73f9e50719096b61fadce8df69046578b7e79a0485a5310dc00658a3eb
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Win32.AutoIt.bpv also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46242114
FireEyeGeneric.mg.8788716f6fd74024
McAfeeDownloader-AutoIt.y
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.150885
K7AntiVirusTrojan ( 0055e3fd1 )
K7GWTrojan ( 0055e3fd1 )
Cybereasonmalicious.f35ddd
CyrenW32/Autoit.YSOJ-3087
ESET-NOD32Win32/Autoit.NNF
APEXMalicious
KasperskyTrojan.Win32.AutoIt.bpv
BitDefenderTrojan.GenericKD.46242114
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.46242114
EmsisoftTrojan.GenericKD.46242114 (B)
DrWebTrojan.DownLoader8.27549
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
SophosGeneric ML PUA (PUA)
GDataTrojan.GenericKD.46242114
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
ALYacTrojan.GenericKD.46242114
MAXmalware (ai score=87)
VBA32Trojan-Downloader.Autoit.gen
MalwarebytesMalware.AI.1699104522
RisingTrojan.StartPage/Autoit!1.D84C (CLASSIC)
IkarusTrojan.Win32.Autoit
eGambitUnsafe.AI_Score_85%
FortinetAutoIt/Autoit.NNF!tr
AVGWin32:Trojan-gen
MaxSecureTrojan.Autoit.AZA

How to remove Trojan.Win32.AutoIt.bpv?

Trojan.Win32.AutoIt.bpv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment