Malware

Win32/Packed.AutoIt.LP removal

Malware Removal

The Win32/Packed.AutoIt.LP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.AutoIt.LP virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the Qulab malware family
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Packed.AutoIt.LP?


File Info:

name: 93FDADFD4FFE4ECC3470.mlw
path: /opt/CAPEv2/storage/binaries/591894186705869cfdb3e517da7cf935f936817d1f93532768a04ad46c51f05d
crc32: 2B6B4DAF
md5: 93fdadfd4ffe4ecc3470a98c6bd0dd39
sha1: d442d5ea2d69be5afd7373e392ac25417dac095b
sha256: 591894186705869cfdb3e517da7cf935f936817d1f93532768a04ad46c51f05d
sha512: 43faeca41fbecf500d67d74382ecac93b80dbad0e89c25ba91ce1f7a0383cd4d48e9a1396e995fbbc8873aff47634cb3922ae68d8a53a1093e71db979a990abe
ssdeep: 49152:9h+ZkldoPK8YaW8iSEo3KGTkPhU38AeAZkgahAGWKvV:u2cPK8S6PwPhK73ZGvWK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDB5F00273D2D036FFAB92738B6AF60556BD79654133852F13982DB9BC701B2263D263
sha3_384: 2b1d5c14fc5ed50a0225d647504bbe58b3c94246f383172de320d79d793eab679e83e6cd0808e6707ce23edde00ec942
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-01-22 20:36:43

Version Info:

Comments: 44CFaZV2pW6NSomElOWYxBIF4W1P2eoePFAVeh62YKO9wQ6uxBBWOU2IvsMcxHn
CompanyName: 32-разрядная библиотека Windows Socket 2.0
FileDescription: Драйвер MCI DirectShow
FileVersion: 9.6.7.2
InternalName: fc.exe
OriginalFilename: fc.exe
ProductVersion: 9.6.7.2
Translation: 0x0809 0x04b0

Win32/Packed.AutoIt.LP also known as:

LionicTrojan.Win32.Autoit.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.17.rw0@aityYeii
ALYacGen:Trojan.Heur.AutoIT.17.rw0@aityYeii
Cylanceunsafe
SangforVirus.Win32.Save.a
BitDefenderGen:Trojan.Heur.AutoIT.17.rw0@aityYeii
Cybereasonmalicious.d4ffe4
ArcabitTrojan.Heur.AutoIT.17.E73133
CyrenW32/AutoIt.IA.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.AutoIt.LP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Autoit.abuge
AlibabaTrojan:Win32/Generic.aca7cc82
NANO-AntivirusTrojan.Win32.Autoit.fnjmcn
TencentWin32.Trojan.Autoit.Zwhl
EmsisoftGen:Trojan.Heur.AutoIT.17.rw0@aityYeii (B)
F-SecureHeuristic.HEUR/AGEN.1245452
DrWebTrojan.PWS.Stealer.25999
VIPREGen:Trojan.Heur.AutoIT.17.rw0@aityYeii
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.93fdadfd4ffe4ecc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Autoit
AviraHEUR/AGEN.1245452
XcitiumMalware@#t520gyp1f791
MicrosoftTrojan:Win32/Occamy.C59
GDataGen:Trojan.Heur.AutoIT.17.rw0@aityYeii
GoogleDetected
AhnLab-V3Trojan/Win32.AutoIt.C2988670
McAfeeArtemis!93FDADFD4FFE
MAXmalware (ai score=88)
VBA32Trojan.Autoit
MalwarebytesTrojan.Qulab.AutoIt.Generic
PandaTrj/Genetic.gen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Packed.AutoIt.LP?

Win32/Packed.AutoIt.LP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment