Crack

About “Win32/HackTool.Autoit.D potentially unsafe” infection

Malware Removal

The Win32/HackTool.Autoit.D potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HackTool.Autoit.D potentially unsafe virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/HackTool.Autoit.D potentially unsafe?


File Info:

crc32: A493E73C
md5: 21a3a489a6b36ee93d43fa2b50ae8d48
name: ShowHidden.exe
sha1: 2ced50c8fb60a0b923b4c7014b9414af99b4166d
sha256: 8a9808c2886f2f1082cce1533a8a068e46d16e5a969fefb0017a2a422b83493c
sha512: 187cfe3c0216f6b1d91f291c59ec80cf98931fb10ede3d53968341b6040f904a263d4f67fc809dabf22c40f038deb62074847035594743532875a54227ccd724
ssdeep: 6144:HRAgmiZ0BG3T8lpR7bM0HBKkZsnKrogOPxeNi:HGgt068RPhxGnKro1xe0
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2014xff0cx5c0fx5175x3002x4fddx7559x6240x6709x6743x5229x3002
FileDescription: x53f3x952ex6269x5c55x529fx80fd (x663ex793a/x9690x85cfx7cfbx7edfx6587x4ef6+x6269x5c55x540d)
FileVersion: 5.0
Comments: x4ee5x4e0bx5730x5740x53efx83b7x53d6x6700x65b0x7248x672c http://www.7xiazai.com
CompanyName: x5c0fx5175
Translation: 0x0809 0x04b0

Win32/HackTool.Autoit.D potentially unsafe also known as:

MicroWorld-eScanTrojan.GenericKD.2067825
FireEyeTrojan.GenericKD.2067825
McAfeeArtemis!21A3A489A6B3
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.2067825
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9a6b36
SymantecTrojan.Gen
ESET-NOD32Win32/HackTool.Autoit.D potentially unsafe
AvastWin32:GenMalicious-EOP [Trj]
GDataTrojan.GenericKD.2067825
KasperskyTrojan.Win32.Agent.amfzm
AlibabaTrojan:Win32/Agent.e225f3e8
NANO-AntivirusTrojan.Win32.Agent.dseqtv
AegisLabTrojan.Win32.Agent.4!c
TencentWin32.Trojan.Agent.Hqbr
Ad-AwareTrojan.GenericKD.2067825
SophosGeneric PUA CM (PUA)
ComodoMalware@#1qelps0g5l48s
F-SecureTrojan.TR/Rogue.244355
TrendMicroTROJ_GEN.R020C0OCM19
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.2067825 (B)
WebrootW32.Malware.Heur
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D1F8D71
ZoneAlarmTrojan.Win32.Agent.amfzm
MicrosoftTrojan:Win32/Dynamer!ac
AhnLab-V3Trojan/Win32.HDC.C710161
VBA32Trojan.Agent
ALYacTrojan.GenericKD.2067825
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R020C0OCM19
FortinetW32/Agent.AMFZM!tr
AVGWin32:GenMalicious-EOP [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/HackTool.Autoit.D potentially unsafe?

Win32/HackTool.Autoit.D potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment