Malware

Win32/Autoit.PU removal guide

Malware Removal

The Win32/Autoit.PU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Autoit.PU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Installs itself for autorun at Windows startup
  • CAPE detected the shellcode get eip malware family
  • Attempts to masquerade or mimic a legitimate process or file name
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Autoit.PU?


File Info:

name: 26AE4AA1344214667121.mlw
path: /opt/CAPEv2/storage/binaries/7521ee02fbd5dc0a555d60764baddfbd9221cf89a1f8490f81de34d16c112957
crc32: A123E983
md5: 26ae4aa134421466712168e41e314ba6
sha1: 5ae62fbf769a084c1e4254b19c92aee98e4d1d37
sha256: 7521ee02fbd5dc0a555d60764baddfbd9221cf89a1f8490f81de34d16c112957
sha512: 96aec7eef8ad91a052a293acf220738fe8e5ecd997a5372b508317578fd82f64b6a48b4e25558631e437b1143ed1eb99c59afd533a1f8baca05d11ccfd5f5cc4
ssdeep: 12288:ihkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNmS3c2k:CRmJkcoQricOIQxiZY1WNmSs2k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191E4AF21F5C68036C2B327B19E7EF76A9A3D79360336D19727C82D315EA05816B29733
sha3_384: b060a61f18523f9c00ead204afb6c5bdf3abbe772d1e448a86f4e1a53ad38a79cb5019489f859048c90a953066575748
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Win32/Autoit.PU also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.104913
ClamAVWin.Malware.Autoit-6991628-0
FireEyeGeneric.mg.26ae4aa134421466
CAT-QuickHealTrojan.Skeeyah.S11718
SkyhighBehavesLike.Win32.Ransomware.jh
McAfeeW32/Worm-FMA!26AE4AA13442
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Strictor.104913
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.AutoIt.a
SymantecW32.SillyFDC
ESET-NOD32Win32/Autoit.PU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Autoit.aza
BitDefenderGen:Variant.Strictor.104913
NANO-AntivirusTrojan.Script.AutoIt.dbycya
AvastAutoIt:Agent-DP [Trj]
TencentTrojan.Win32.Agent.hab
SophosMal/Sohana-A
F-SecureTrojan.TR/AutoIt.axovq
DrWebTrojan.DownLoader6.18661
ZillyaTrojan.AutoIT.Win32.13710
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.104913 (B)
IkarusTrojan.Crypt
GoogleDetected
AviraTR/AutoIt.axovq
Antiy-AVLTrojan/Win32.Autoit
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumTrojWare.Win32.Agent.AZAB@59q48x
ArcabitTrojan.Strictor.D199D1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1GHRIQ4
VaristW32/AutoIt.AQ2.gen!Eldorado
AhnLab-V3Trojan/Win32.Rootkit.C210334
BitDefenderThetaAI:Packer.FCE2514219
MAXmalware (ai score=82)
VBA32Trojan.Autoit.Wirus
Cylanceunsafe
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.OH!worm
AVGAutoIt:Agent-DP [Trj]
Cybereasonmalicious.f769a0
DeepInstinctMALICIOUS

How to remove Win32/Autoit.PU?

Win32/Autoit.PU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment