Trojan

TrojanDropper:AutoIt/Binder removal instruction

Malware Removal

The TrojanDropper:AutoIt/Binder is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:AutoIt/Binder virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
goodman20.no-ip.org

How to determine TrojanDropper:AutoIt/Binder?


File Info:

crc32: 02C9893C
md5: 96afc6d2ee29b1758eb925d3a7a8264d
name: 96AFC6D2EE29B1758EB925D3A7A8264D.mlw
sha1: 0b2ee2a6b54e958122af65bc47da17cda62cf2c6
sha256: 21108ce1f10b8fb0117fcbc1f45cf2deecf654053f305d5f49b04caf364e6f1c
sha512: eb5bd3bb90d782fcfcd20ba47c52f532adf05038129443b876fb9de20033196e26844d7edce91e1191782430bcdc6ac99872c65e1073cd967c5114170955ef8d
ssdeep: 24576:uRmJkcoQricOIQxiZY1iaC6Z8/HZmi9syeusIGWQYxlQf:7JZoQrbTFZY1iaCv/5pu9usrWplm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

TrojanDropper:AutoIt/Binder also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 700000111 )
Elasticmalicious (high confidence)
DrWebBackDoor.Comet.152
CynetMalicious (score: 100)
ALYacAIT:Trojan.Nymeria.4263
CylanceUnsafe
ZillyaBackdoor.Delf.Win32.17171
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000111 )
Cybereasonmalicious.2ee29b
CyrenW32/AutoIt.AQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Agent-OU [Trj]
KasperskyUDS:Backdoor.Win32.DarkKomet.xyk
BitDefenderAIT:Trojan.Nymeria.4263
NANO-AntivirusTrojan.Win32.Delf.clocjg
MicroWorld-eScanAIT:Trojan.Nymeria.4263
TencentWin32.Backdoor.Delf.Hupr
Ad-AwareAIT:Trojan.Nymeria.4263
SophosMal/Generic-R + Troj/Zbot-DOO
ComodoMalware@#57i3js3ivn32
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Yahlover.tc
FireEyeGeneric.mg.96afc6d2ee29b175
EmsisoftAIT:Trojan.Nymeria.4263 (B)
JiangminTrojan.Script.affl
AviraHEUR/AGEN.1110303
KingsoftWin32.Hack.Delf.ah.(kcloud)
MicrosoftTrojanDropper:AutoIt/Binder
GDataAIT:Trojan.Nymeria.4263 (2x)
AhnLab-V3Trojan/Win32.Autoit.C2428887
McAfeeArtemis!96AFC6D2EE29
MAXmalware (ai score=87)
VBA32Trojan.Autoit.F
MalwarebytesMalware.AI.4232914048
PandaTrj/CI.A
IkarusTrojan.Backdoor.Rat
MaxSecureTrojan.Autoit.AZA
FortinetW32/Injector_Autoit.EI!tr
AVGAutoIt:Agent-OU [Trj]
Paloaltogeneric.ml

How to remove TrojanDropper:AutoIt/Binder?

TrojanDropper:AutoIt/Binder removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment