Trojan

Trojan.Win32.Autoit.fdg removal instruction

Malware Removal

The Trojan.Win32.Autoit.fdg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Autoit.fdg virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Exhibits behavior characteristic of Nanocore RAT
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Autoit.fdg?


File Info:

crc32: 8EED0DE7
md5: add3c9f3affc7afd731afbff505be446
name: ADD3C9F3AFFC7AFD731AFBFF505BE446.mlw
sha1: 9e96fc30c4133ff65a70cba9cb57d4f940bbdc4b
sha256: d164b300f2357f95493a9678dfb52408354f29de07bd491fca7ee23904686a78
sha512: ba47c1640f6f2431d07399699d32ada78f16f3ce7898bca2bc2236377b3779ed109634afc120735dd550e5d9d4b2c62188e6fa3b920844b6f6c51784724da039
ssdeep: 24576:+po/2+ttPJLfpRK+QB4s4bFXbA9AxzaxDQO5zVsJxjtruwqRkVTXrJbB45bEFp:He2PJLa+Qj4lGpzV2xuwHvJbB4ED
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script : 3, 3, 0, 0
FileVersion: 3, 3, 0, 0
FileDescription:
Translation: 0x0809 0x04b0

Trojan.Win32.Autoit.fdg also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 0055e3ec1 )
LionicTrojan.Win32.Autoit.4!c
DrWebTrojan.PWS.Stealer.17428
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.3370661
CylanceUnsafe
ZillyaWorm.AutoitGen.Win32.844
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Injector.c7c7abbe
K7GWSpyware ( 0055e3ec1 )
Cybereasonmalicious.3affc7
SymantecTrojan.Gen
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Autoit-9895204-0
KasperskyTrojan.Win32.Autoit.fdg
BitDefenderTrojan.GenericKD.3370661
NANO-AntivirusTrojan.Script.Agent.debxaj
MicroWorld-eScanTrojan.GenericKD.3370661
TencentWin32.Trojan.Autoit.Lrih
Ad-AwareTrojan.GenericKD.3370661
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Yahlover.th
FireEyeGeneric.mg.add3c9f3affc7afd
EmsisoftTrojan.GenericKD.3370661 (B)
JiangminTrojan.Autoit.hnq
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1105049
KingsoftWin32.Troj.Autoit.f.(kcloud)
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
GDataTrojan.GenericKD.3370661
McAfeeArtemis!ADD3C9F3AFFC
MAXmalware (ai score=100)
VBA32Trojan.Autoit.Injcrypt
PandaTrj/CI.A
IkarusTrojan.MSIL.Spy
MaxSecureWorm.Win32.AutoIt.QN
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Autoit.fdg?

Trojan.Win32.Autoit.fdg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment