Malware

Win32/Packed.AutoIt.JJ removal guide

Malware Removal

The Win32/Packed.AutoIt.JJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.AutoIt.JJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates running processes
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Packed.AutoIt.JJ?


File Info:

name: 6C7522304CFB9C6792E5.mlw
path: /opt/CAPEv2/storage/binaries/38f9e721f84676e671d790009cc4b539d3e87216af8f3b2fc7000484165ef716
crc32: B2DB5A69
md5: 6c7522304cfb9c6792e54f92704d1229
sha1: a27a4d03d39774bcbee1087d35a96975497a2d19
sha256: 38f9e721f84676e671d790009cc4b539d3e87216af8f3b2fc7000484165ef716
sha512: ddaed9430e71a25b12f7a6d0dbb630317c50e974318d009b5119495210604a34214a9d77dda908fe468f0027a7d46b1192898b2bf265e5f78aa43175b1031a43
ssdeep: 24576:FAHnh+eWsN3skA4RV1Hom2KXMmHafbe189CGHvDFbohIz5:0h+ZkldoPK8Yafy1o9PDFoi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11145BE0273D1D036FFABA2739B6AB20596BD79250133852F13981DB9BD701B1237E663
sha3_384: 5d061d8e9c28782391a2b8d07847a713558435856eba86a1cb953719b375632800eb949855313b30a8ad1bf0cf6868b6
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2018-08-30 11:35:39

Version Info:

FileVersion: 6.6.2.4
ProductVersion: 6.6.2.4
FileDescription: COM+
CompanyName: WSMAN Automation
LegalCopyright: (C) DyEQseIy56ssI3EtnO4uYDGQpH6MpT9MkYRkIr5wQq4bVEZfpRP Technology Co. Ltd., All rights reserved.
ProductName:
Comments: lPInIlcxqMLmbrrGmZNtEDRY2pBAypOcAPFxF1bMUQIhPGRbc34BNiw7KFHaqrEDKWP9Ccm649OBvTLm5OdMU52U21RqropbtHkWFvy6sk
InternalName: Taskmgr.exe
Translation: 0x0000 0x04b0

Win32/Packed.AutoIt.JJ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.17jv0@aaDTvNhi
FireEyeGeneric.mg.6c7522304cfb9c67
ALYacGen:Trojan.Heur.AutoIT.17jv0@aaDTvNhi
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win64/Miner.b19d29ed
K7GWTrojan ( 700000111 )
Cybereasonmalicious.04cfb9
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Packed.AutoIt.JJ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan.Win64.Miner.gry
BitDefenderGen:Trojan.Heur.AutoIT.17jv0@aaDTvNhi
NANO-AntivirusTrojan.Win32.Mlw.fiblwh
TencentWin64.Trojan.Miner.Wqwz
Ad-AwareGen:Trojan.Heur.AutoIT.17jv0@aaDTvNhi
SophosMal/Generic-S
ComodoMalware@#3mgovdz2va3nm
DrWebTrojan.DownLoader26.64715
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftGen:Trojan.Heur.AutoIT.17jv0@aaDTvNhi (B)
Paloaltogeneric.ml
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1100133
GridinsoftRansom.Win32.Gen.sa
GDataGen:Trojan.Heur.AutoIT.17jv0@aaDTvNhi
AhnLab-V3Trojan/Win32.Agent.R285246
McAfeeArtemis!6C7522304CFB
MalwarebytesTrojan.BitCoinMiner.AutoIt
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
eGambitUnsafe.AI_Score_99%
FortinetW64/Miner.GRY!tr
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Packed.AutoIt.JJ?

Win32/Packed.AutoIt.JJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment