Trojan

VHO:Trojan.Win32.AutoItScript information

Malware Removal

The VHO:Trojan.Win32.AutoItScript is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan.Win32.AutoItScript virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine VHO:Trojan.Win32.AutoItScript?


File Info:

crc32: 61AA3102
md5: e4711c5a41f9811656f21c1bcc48c675
name: E4711C5A41F9811656F21C1BCC48C675.mlw
sha1: a9f9f0cab7850e7ad42eb4ff1ba0790ef7028444
sha256: 95a0acbafa4f9852dfaa2f270dd2efdabfe1df4dc84cc11df5ef56f7112319b7
sha512: bb5a5ebb03a3e44a7862c4c5b14f4a8edde2715d11c58a33d1a661e97b9190c297b22f95db007c70267fa98fee72d4c7a6a894edeb018ebdf9d8cae7777f738d
ssdeep: 12288:CCdOy3vVrKxR5CXbNjAOxK/j2n+4YG/6c1mFFja3mXgcjfJilgsUFc/lBD6jLhZ:CCdxte/80jYLT3U1jfH5cdBD6hsH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductName: fsociety
FileDescription: You Have Been Chosen
CompanyName: 2017
Translation: 0x0809 0x04b0

VHO:Trojan.Win32.AutoItScript also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005093361 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.48152
CynetMalicious (score: 100)
ALYacZum.Ransom.Philadelphia.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Philadelphia.de461753
K7GWTrojan ( 005093361 )
Cybereasonmalicious.a41f98
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Filecoder.Philadelphia.F
APEXMalicious
AvastAutoIt:Injector-IU [Trj]
KasperskyVHO:Trojan.Win32.AutoItScript.gen
BitDefenderAIT:Trojan.Nymeria.4286
NANO-AntivirusTrojan.Win32.Autoruner2.fkeofs
MicroWorld-eScanAIT:Trojan.Nymeria.4286
TencentWin32.Worm.Filecoder.Ajkz
Ad-AwareAIT:Trojan.Nymeria.4286
SophosMal/Generic-R + Troj/Stampado-A
ComodoMalware@#3cm6952x5elvk
BitDefenderThetaAI:Packer.B4380A1715
TrendMicroRansom_STAMPADO.SMAUIT1
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.fh
FireEyeGeneric.mg.e4711c5a41f98116
EmsisoftAIT:Trojan.Nymeria.4286 (B)
AviraHEUR/AGEN.1139477
eGambitUnsafe.AI_Score_77%
MicrosoftTrojan:Win32/Occamy.B
ArcabitAIT:Trojan.Nymeria.D10BE
GDataZum.Ransom.Philadelphia.1
AhnLab-V3Malware/Win32.Ransom_stampado.C2861708
Acronissuspicious
McAfeeArtemis!E4711C5A41F9
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3781033074
TrendMicro-HouseCallRansom_STAMPADO.SMAUIT1
RisingTrojan.Obfus/Autoit!1.BEDE (CLASSIC)
IkarusWorm.Win32.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Philadelphia.4936!tr.ransom
AVGAutoIt:Injector-IU [Trj]

How to remove VHO:Trojan.Win32.AutoItScript?

VHO:Trojan.Win32.AutoItScript removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment