Malware

Win32/Packed.AutoIt.UB malicious file

Malware Removal

The Win32/Packed.AutoIt.UB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.AutoIt.UB virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.telegram.org
ipapi.co

How to determine Win32/Packed.AutoIt.UB?


File Info:

crc32: B156814B
md5: 368d77519fe89cb250fad82c772381c4
name: 1.exe
sha1: 452d3a172280f13713b8f27b9c10303e622f24cc
sha256: d53454daa1ac0a9235d34f57ad179710fe1cb9c66167fe21dcbd1f0b89d26a38
sha512: cc583d4f1871956ca6ac787abceb700288c4fe9bbf56535fbfee3d072d4a6c4f74edab59aaaabc84565f7554af18bce80aceffd79c91c3a1490ed359f9c810d3
ssdeep: 49152:4h+ZkldoPK8Ya/eW7kZhv4l2WWcvAkLmmlt9XMe8yvZa9rKUcREbG:52cPK84W7kZycVOtdM6veKUcR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: TCPSVCS.EXE
FileVersion: 5.99007211951539.3.01504588965327.4.78005218040198.2.12082689860836
CompanyName: Windows Runtime Brightness Override DLL
Comments: 1xd835xdd18xd835xdd35xd835xdd1fxd835xdd04xd835xdd20xd835xdd05xd835xdd2cxd835xdd2cxd835xdd25xd835xdd37xd835xdd28xd835xdd13xd835xdd37xd835xdd31xd835xdd09xd835xdd37x211cxd835xdd09xd835xdd17xd835xdd14xd835xdd33xd835xdd191xd835xdd2a2xd835xdd22xd835xdd1bxd835xdd33xd835xdd188x212883xd835xdd19xd835xdd17xd835xdd30xd835xdd11xd835xdd05xd835xdd33xd835xdd32xd835xdd17xd835xdd2axd835xdd24xd835xdd1exd835xdd1fxd835xdd16xd835xdd29xd835xdd28xd835xdd09xd835xdd2cx211cxd835xdd18xd835xdd1cxd835xdd19xd835xdd12xd835xdd24xd835xdd18
ProductVersion: 5.99007211951539.3.01504588965327.4.78005218040198.2.12082689860836
FileDescription: Maps Background Transfer Service
OriginalFilename: TCPSVCS.EXE
Translation: 0x0809 0x04b0

Win32/Packed.AutoIt.UB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33293705
FireEyeTrojan.GenericKD.33293705
Qihoo-360Win32/Trojan.PSW.261
ALYacTrojan.GenericKD.33293705
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.GenericKD.33293705
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R03BH07BK20
AvastScript:SNH-gen [Trj]
ClamAVWin.Malware.Autoit-6985537-0
GDataTrojan.GenericKD.33293705
KasperskyTrojan-PSW.Win32.Xploder.lz
AlibabaTrojanPSW:Win32/Xploder.3082d9ff
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan-qqpass.Qqrob.Lkef
Ad-AwareTrojan.GenericKD.33293705
EmsisoftTrojan.GenericKD.33293705 (B)
F-SecureTrojan.TR/PSW.Stealer.ahdyu
DrWebTrojan.PWS.Stealer.27517
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
APEXMalicious
CyrenW32/Trojan.YPHM-7011
AviraTR/PSW.Stealer.ahdyu
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FC0589
ZoneAlarmTrojan-PSW.Win32.Xploder.lz
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!368D77519FE8
MAXmalware (ai score=87)
VBA32TrojanPSW.Stealer
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.AutoIt.UB
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
YandexTrojan.AvsArher.bS970C
IkarusTrojan.Win32.Autoit
eGambitUnsafe.AI_Score_96%
FortinetAutoIt/Packed.OH!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Packed.AutoIt.UB?

Win32/Packed.AutoIt.UB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment