Malware

Win32/Packed.AutoIt.KL removal tips

Malware Removal

The Win32/Packed.AutoIt.KL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.AutoIt.KL virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

yip.su

How to determine Win32/Packed.AutoIt.KL?


File Info:

crc32: 3433D2AC
md5: 4449b10079c037ee122ab71b5a498301
name: 4449B10079C037EE122AB71B5A498301.mlw
sha1: edc87274f102c0bccff54fd9724ed5999d9c5a2f
sha256: fabd6718ee932e0f59ac30ef49de2f553f6224b8ab0d74e6d3121567fa255e02
sha512: 17564e8b326fc2c20de00ae3adacc75e759ba06eafd70f84e9273e35f40297b1e836ba8a101f4b703ca90f0a6923fc5351ba1395661945392eb65722bf0d814f
ssdeep: 24576:zAHnh+eWsN3skA4RV1Hom2KXMmHa6bBnbWGpkS+ikOGG4UP99R5:+h+ZkldoPK8Ya6VbWGeXK4UPP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) e418Sg1ABfPFXaI8LYDRwa8eMSkEOZv8Cpq7x9wTXZ6bHova3d9c48zfkBkVT Technology Co. Ltd., All rights reserved.
InternalName: cttune.exe
FileVersion: 4.1.4.7
CompanyName: Windows Connect Now - WCN EAP PEER Proxy
Comments: HcPxuSyiGcp1y722yS2MZ8U9bfM1592mDbYyWOpTMcTDZAryqc4pFXpGzcbV2ce8Q2wtE5c1WECAZWPnsVvMsZHNCbRMRLhSerFeil3gUZN1sSE
ProductVersion: 4.1.4.7
FileDescription: Microsoft Neutral Natural Language Server Data and Code
OriginalFilename: cttune.exe
Translation: 0x0809 0x04b0

Win32/Packed.AutoIt.KL also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.21384
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.AutoIT.17lv0@aqnf@Qni
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2c67698.None
K7GWTrojan ( 700000111 )
Cybereasonmalicious.079c03
CyrenW32/AutoIt.HJ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Packed.AutoIt.KL
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Script.Generic
BitDefenderGen:Trojan.Heur.AutoIT.17lv0@aqnf@Qni
NANO-AntivirusTrojan.Win32.Mlw.flfvht
MicroWorld-eScanGen:Trojan.Heur.AutoIT.17lv0@aqnf@Qni
Ad-AwareGen:Trojan.Heur.AutoIT.17lv0@aqnf@Qni
SophosMal/Generic-S
ComodoMalware@#26ai5tew7u070
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.4449b10079c037ee
EmsisoftGen:Trojan.Heur.AutoIT.17lv0@aqnf@Qni (B)
AviraHEUR/AGEN.1100133
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/CoinMiner.C!rfn
GDataGen:Trojan.Heur.AutoIT.17lv0@aqnf@Qni
McAfeeArtemis!4449B10079C0
MAXmalware (ai score=100)
VBA32Trojan.CoinMiner
MalwarebytesTrojan.BitCoinMiner.Generic
PandaTrj/Genetic.gen
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
IkarusTrojan.Win32.Autoit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Packed.AutoIt.KL?

Win32/Packed.AutoIt.KL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment