Malware

Win32/Packed.AutoIt.KY removal tips

Malware Removal

The Win32/Packed.AutoIt.KY file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Packed.AutoIt.KY virus can do?

  • Drops a binary and executes it
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Packed.AutoIt.KY?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Trojan.GenericKD.32704770

File Info:

Name: rss.exe

Size: 1003520

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 3c994d9e67f627add95e6040e9a4c28a

SHA1: d6ee9545b6c062039038420536d7363ff4f7769f

SH256: 4369ee57177431e9be048e8790a48c27c34b48447d056f12996ec37679fa5bcb

Version Info:

[No Data]

Win32/Packed.AutoIt.KY also known as:

ALYacTrojan.GenericKD.32704770
APEXMalicious
AVGWin32:Trojan-gen
Acronissuspicious
Ad-AwareTrojan.GenericKD.32704770
AegisLabTrojan.Win32.Generic.4!c
AhnLab-V3Malware/Win32.Generic.C3559340
AlibabaTrojanBanker:Win32/ClipBanker.d520ac47
Antiy-AVLTrojan/Generic.ASVCS3S.1E5
ArcabitTrojan.Generic.D1F30902
AvastWin32:Trojan-gen
AviraHEUR/AGEN.1036560
BitDefenderTrojan.GenericKD.32704770
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CyrenW32/Trojan.DBTN-4321
ESET-NOD32a variant of Win32/Packed.AutoIt.KY
Endgamemalicious (high confidence)
F-SecureHeuristic.HEUR/AGEN.1036560
FireEyeGeneric.mg.3c994d9e67f627ad
GDataTrojan.GenericKD.32704770
IkarusTrojan.Win32.Autoit
Invinceaheuristic
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
KasperskyTrojan-Banker.Win32.ClipBanker.gqq
MalwarebytesTrojan.ClipBanker.AutoIt.Generic
MaxSecureTrojan.Malware.300983.susgen
McAfeeRDN/Generic.grp
McAfee-GW-EditionBehavesLike.Win32.Downloader.dh
MicroWorld-eScanTrojan.GenericKD.32704770
MicrosoftTrojan:Win32/Occamy.C
NANO-AntivirusTrojan.Win32.ClipBanker.ghejfj
Paloaltogeneric.ml
PandaTrj/CI.A
Qihoo-360HEUR/QVM10.2.287D.Malware.Gen
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R023C0PKE19
ZoneAlarmTrojan-Banker.Win32.ClipBanker.gqq

How to remove Win32/Packed.AutoIt.KY?

Win32/Packed.AutoIt.KY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment