Malware

Win32/Autoit.PU (file analysis)

Malware Removal

The Win32/Autoit.PU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Autoit.PU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the shellcode get eip malware family
  • Attempts to masquerade or mimic a legitimate process or file name
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Autoit.PU?


File Info:

name: 115B993122A527807FB9.mlw
path: /opt/CAPEv2/storage/binaries/d3ea1c6f8faad5a8279f7ddb75196749ebaffd6e4d2f96b39dc118e7dbd0b463
crc32: C0B968AB
md5: 115b993122a527807fb9653fc37f87db
sha1: 87e4e3a31c3e9c1da4cb0b36aceab2e7b4af6ef4
sha256: d3ea1c6f8faad5a8279f7ddb75196749ebaffd6e4d2f96b39dc118e7dbd0b463
sha512: 5a8912b855d98122e01afe12e9823bbd552195323332b8ff6c6d38a296ed8e3a763e45a87ef6e9744482108f1e266415ca2400c361454d7529a7e3dd8df66e42
ssdeep: 12288:1hkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNlS3c22:DRmJkcoQricOIQxiZY1WNlSs22
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183E4AF21F5C68036C2B327B19E7EF76A9A3D79360336D19727C82D315EA05816B29733
sha3_384: 56ed921fd11985e2598b2a7b54d9bc8c8c49f973fbb408d98bb6b923fa13b0fb9d99bb4169c501656ef51681b29e4906
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Win32/Autoit.PU also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.AutoIt.4!c
tehtrisGeneric.Malware
DrWebTrojan.DownLoader6.18661
MicroWorld-eScanGen:Variant.Strictor.104913
ClamAVWin.Malware.Autoit-6991628-0
FireEyeGeneric.mg.115b993122a52780
CAT-QuickHealTrojan.Skeeyah.S11718
SkyhighBehavesLike.Win32.Ransomware.jh
McAfeeW32/Worm-FMA!115B993122A5
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Strictor.104913
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaWorm:Win32/Moarider.98bd7824
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.FCE2514219
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32Win32/Autoit.PU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Autoit.aza
BitDefenderGen:Variant.Strictor.104913
NANO-AntivirusTrojan.Script.AutoIt.dbycya
AvastAutoIt:Agent-DP [Trj]
TencentTrojan.Win32.Agent.hab
EmsisoftGen:Variant.Strictor.104913 (B)
F-SecureTrojan.TR/AutoIt.axovq
BaiduWin32.Trojan.AutoIt.a
ZillyaTrojan.AutoIT.Win32.13710
TrendMicroTROJ_GEN.R002C0CA524
SophosMal/Sohana-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1GHRIQ4
GoogleDetected
AviraTR/AutoIt.axovq
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Autoit
Kingsoftmalware.kb.a.954
XcitiumTrojWare.Win32.Agent.AZAB@59q48x
ArcabitTrojan.Strictor.D199D1
ZoneAlarmUDS:Trojan.Win32.Autoit.aza
MicrosoftWorm:Win32/Moarider.A
VaristW32/AutoIt.AQ2.gen!Eldorado
AhnLab-V3Trojan/Win.Rootkit.R574020
VBA32Trojan.Autoit.Wirus
ALYacGen:Variant.Strictor.104913
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0CA524
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.OH!worm
AVGAutoIt:Agent-DP [Trj]
Cybereasonmalicious.31c3e9
DeepInstinctMALICIOUS

How to remove Win32/Autoit.PU?

Win32/Autoit.PU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment