Malware

Win32/Packed.AutoIt.LR removal guide

Malware Removal

The Win32/Packed.AutoIt.LR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.AutoIt.LR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares

How to determine Win32/Packed.AutoIt.LR?


File Info:

name: 93FDADFD4FFE4ECC3470.mlw
path: /opt/CAPEv2/storage/binaries/591894186705869cfdb3e517da7cf935f936817d1f93532768a04ad46c51f05d
crc32: 2B6B4DAF
md5: 93fdadfd4ffe4ecc3470a98c6bd0dd39
sha1: d442d5ea2d69be5afd7373e392ac25417dac095b
sha256: 591894186705869cfdb3e517da7cf935f936817d1f93532768a04ad46c51f05d
sha512: 43faeca41fbecf500d67d74382ecac93b80dbad0e89c25ba91ce1f7a0383cd4d48e9a1396e995fbbc8873aff47634cb3922ae68d8a53a1093e71db979a990abe
ssdeep: 49152:9h+ZkldoPK8YaW8iSEo3KGTkPhU38AeAZkgahAGWKvV:u2cPK8S6PwPhK73ZGvWK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDB5F00273D2D036FFAB92738B6AF60556BD79654133852F13982DB9BC701B2263D263
sha3_384: 2b1d5c14fc5ed50a0225d647504bbe58b3c94246f383172de320d79d793eab679e83e6cd0808e6707ce23edde00ec942
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-01-22 20:36:43

Version Info:

Comments: 44CFaZV2pW6NSomElOWYxBIF4W1P2eoePFAVeh62YKO9wQ6uxBBWOU2IvsMcxHn
CompanyName: 32-разрядная библиотека Windows Socket 2.0
FileDescription: Драйвер MCI DirectShow
FileVersion: 9.6.7.2
InternalName: fc.exe
OriginalFilename: fc.exe
ProductVersion: 9.6.7.2
Translation: 0x0809 0x04b0

Win32/Packed.AutoIt.LR also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.25999
MicroWorld-eScanGen:Trojan.Heur.AutoIT.17rw0@aityYeii
ALYacGen:Trojan.Heur.AutoIT.17rw0@aityYeii
CylanceUnsafe
AlibabaTrojan:Win32/Generic.aca7cc82
Cybereasonmalicious.d4ffe4
CyrenW32/AutoIt.IA.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Packed.AutoIt.LR
Paloaltogeneric.ml
KasperskyTrojan.Win32.Autoit.abuge
BitDefenderGen:Trojan.Heur.AutoIT.17rw0@aityYeii
NANO-AntivirusTrojan.Win32.Autoit.fnjmcn
AvastFileRepMalware
TencentWin32.Trojan.Autoit.Hvjh
EmsisoftGen:Trojan.Heur.AutoIT.17rw0@aityYeii (B)
ComodoMalware@#t520gyp1f791
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vc
FireEyeGeneric.mg.93fdadfd4ffe4ecc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Autoit
AviraHEUR/AGEN.1100081
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Occamy.C59
GDataGen:Trojan.Heur.AutoIT.17rw0@aityYeii
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.AutoIt.C2988670
McAfeeArtemis!93FDADFD4FFE
VBA32Trojan.Autoit
MalwarebytesTrojan.Qulab.AutoIt.Generic
APEXMalicious
FortinetW32/PossibleThreat
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Packed.AutoIt.LR?

Win32/Packed.AutoIt.LR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment